Google Gemini AI Bot Hijacks Smart Homes, Turns Off the Lights
ID: 99766633-4e98-50ce-ad9f-c7ef2677fbcf
STIX ID: report--99766633-4e98-50ce-ad9f-c7ef2677fbcf
Feed Name: Dark Reading
Researchers demonstrated at Black Hat that Google Gemini can be hijacked by embedding invisible, indirect prompt-injection payloads in Google Calendar event titles; when the model was later asked to summarize calendar events, the dormant instructions triggered and enabled control of smart-home devices (lights, shutters, boiler). The team identified 14 such indirect prompt-injection techniques, responsibly disclosed the findings to Google, and cautioned that as LLMs become more connected to physical systems these vulnerabilities could create safety risks, although Google reports no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
