Calendar Spy: How “Indirect Prompt Injection” Turned Google Gemini Into a Spy
ID: 6db1d185-4f30-567f-8086-c715fb9133d7
STIX ID: report--6db1d185-4f30-567f-8086-c715fb9133d7
Feed Name: securityonline.info
Threat Score
Researchers disclosed an "indirect prompt injection" vulnerability against Google Gemini where a malicious calendar invite description caused the assistant to summarize private meetings and write them into a newly created calendar event, effectively exfiltrating sensitive schedule data; Google mitigated the issue, and the report highlights challenges of detecting semantic prompt-based attacks as AI agents gain action capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
