logo

Gemini Enterprise No-Click Flaw Exposes Sensitive Data

ID: 78bbe8da-119e-5127-b589-eff43d56d446

STIX ID: report--78bbe8da-119e-5127-b589-eff43d56d446

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Noma Labs discovered a critical zero-click prompt-injection vulnerability dubbed "GeminiJack" in Google Gemini Enterprise that could be exploited by placing hidden instructions in shared Workspace items (Docs, Calendar, Gmail). When Gemini performed routine searches, it could retrieve the poisoned document, execute the hidden instructions across Gmail/Docs/Calendar, and embed the collected sensitive results into an external image URL, causing silent exfiltration to an attacker-controlled server. Google and Noma validated and remediated the issue by changing retrieval/indexing interactions and separating Vertex AI Search from Gemini Enterprise; the report emphasizes that similar RAG-based AI systems remain at risk and outlines mitigations such as least-privilege connectors, DLP, logging, human-in-the-loop controls, and red‑teaming.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.