Google Gemini Privacy Controls Bypassed to Access Private Meeting Data Using Calendar Invite
ID: 1ca5e087-5163-5afc-9b78-3fc1299ccd40
STIX ID: report--1ca5e087-5163-5afc-9b78-3fc1299ccd40
Feed Name: cybersecurityNews.com
Threat Score
**Executive Summary:** A proof‑of‑concept prompt‑injection vulnerability in Google Gemini allowed attackers to embed natural‑language commands in Google Calendar event descriptions that caused the model to summarize private calendar entries and write them to a new event accessible to the invite creator, enabling stealthy exfiltration of meeting details; the flaw was demonstrated by Miggo and patched by Google following responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
