Gemini Enterprise No-Click Flaw Exposes Sensitive Data
ID: 78bbe8da-119e-5127-b589-eff43d56d446
STIX ID: report--78bbe8da-119e-5127-b589-eff43d56d446
Feed Name: Dark Reading
Date Published: 2025-12-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Noma Labs discovered a critical zero-click prompt-injection vulnerability dubbed "GeminiJack" in Google Gemini Enterprise that could be exploited by placing hidden instructions in shared Workspace items (Docs, Calendar, Gmail). When Gemini performed routine searches, it could retrieve the poisoned document, execute the hidden instructions across Gmail/Docs/Calendar, and embed the collected sensitive results into an external image URL, causing silent exfiltration to an attacker-controlled server. Google and Noma validated and remediated the issue by changing retrieval/indexing interactions and separating Vertex AI Search from Gemini Enterprise; the report emphasizes that similar RAG-based AI systems remain at risk and outlines mitigations such as least-privilege connectors, DLP, logging, human-in-the-loop controls, and red‑teaming.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
