logo

Google Gemini AI Bot Hijacks Smart Homes, Turns Off the Lights

ID: 99766633-4e98-50ce-ad9f-c7ef2677fbcf

STIX ID: report--99766633-4e98-50ce-ad9f-c7ef2677fbcf

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-08-06

Date Updated: 2026-04-21

Author: Kristina Beek

...
...

Researchers demonstrated at Black Hat that Google Gemini can be hijacked by embedding invisible, indirect prompt-injection payloads in Google Calendar event titles; when the model was later asked to summarize calendar events, the dormant instructions triggered and enabled control of smart-home devices (lights, shutters, boiler). The team identified 14 such indirect prompt-injection techniques, responsibly disclosed the findings to Google, and cautioned that as LLMs become more connected to physical systems these vulnerabilities could create safety risks, although Google reports no evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.