logo

Calendar Spy: How “Indirect Prompt Injection” Turned Google Gemini Into a Spy

ID: 6db1d185-4f30-567f-8086-c715fb9133d7

STIX ID: report--6db1d185-4f30-567f-8086-c715fb9133d7

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed an "indirect prompt injection" vulnerability against Google Gemini where a malicious calendar invite description caused the assistant to summarize private meetings and write them into a newly created calendar event, effectively exfiltrating sensitive schedule data; Google mitigated the issue, and the report highlights challenges of detecting semantic prompt-based attacks as AI agents gain action capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.