Google AI Studio fakes data deletion. VRP auto-banned me in 60s for reporting it
This is a real security failure on two fronts: the technical one (data deletion isn't) and the meta one (shooting the messenger with an automated ban suggests zero human review of VRP reports). For builders using Google's AI services, this signals that responsible disclosure could get you blocked from the platform. For anyone shipping data deletion guarantees to users, this is a test case in how not to handle vulnerability reports.