Gemini Zero-Click Vulnerability Allowed Attackers to Access Gmail, Calendar, and Docs
ID: b61af786-a43b-5fd3-bdb6-2828c0e0f43a
STIX ID: report--b61af786-a43b-5fd3-bdb6-2828c0e0f43a
Feed Name: cybersecurityNews.com
A critical zero-click architectural flaw dubbed "GeminiJack" in Google Gemini Enterprise/Vertex AI Search allowed attackers to plant poisoned content in Docs, Calendar events, or emails that RAG-based searches would retrieve and cause the AI to exfiltrate sensitive Workspace data (Gmail, Calendar, Docs) via disguised HTML image requests; Google separated Vertex AI Search from Gemini and patched RAG instruction handling, and the report warns organizations to limit data sources and monitor RAG pipelines to mitigate AI-native prompt-injection risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
