logo

Google Gemini Privacy Controls Bypassed to Access Private Meeting Data Using Calendar Invite

ID: 1ca5e087-5163-5afc-9b78-3fc1299ccd40

STIX ID: report--1ca5e087-5163-5afc-9b78-3fc1299ccd40

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** A proof‑of‑concept prompt‑injection vulnerability in Google Gemini allowed attackers to embed natural‑language commands in Google Calendar event descriptions that caused the model to summarize private calendar entries and write them to a new event accessible to the invite creator, enabling stealthy exfiltration of meeting details; the flaw was demonstrated by Miggo and patched by Google following responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.