logo

Google Gemini Flaw Turns Calendar Invites Into Attack Vector

ID: 9e60ac62-eed3-5d27-a190-35bc032b9b36

STIX ID: report--9e60ac62-eed3-5d27-a190-35bc032b9b36

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers disclosed a prompt-injection vulnerability in Google's Gemini Calendar integration where an attacker can embed a dormant natural-language payload in an event description; when Gemini is later queried about the calendar it executes the payload, summarizes private meetings, and writes that summary into a new calendar event that the attacker can read. The proof-of-concept shows semantic attacks against LLM-integrated apps and recommends defenses that reason about intent, semantics, and data provenance at runtime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.