Credential Access
High
- Category
- Privilege Escalation
- Content
floor, and comes back when it recovers. Nothing has to be switched off and on again for that. The credential comes from the macOS keychain entry `gemini-cli-oauth` (account `main-account`) or from `~/.gemini/oauth_creds.json`. Both the flat file format and the keytar nesting are read, so it does not matter which one the CLI wrote.
- Confidence
- 86% confidence
- Finding
- keychain
