Essentially. I am in no way technical, but my suspicion had been that it was something not even Google was aware could be possible or so effective; by the time they'd caught on, it would have been impossible to reverse without rebuilding the entire thing, having been embedded deeply in the model. The attack being unheard of at the time would then be why it was successful at all.
The alternative is simple oversight, which admittedly would be characteristic of Google's regard for DEI and AI safety. Part of me wants it to be a purposeful rogue move because that alternative kind of sucks more.
>Funnily, they fixed by just removed the gorilla label from their classifier.
I'd heard this, though I think it's more unfortunate than funny. There are a lot of other common terms that you can't search for in Google Photos, in particular, and I wouldn't be surprised to find that they were removed because of similarly unfortunate associations. It severely limits search usability.