Indirect Prompt Injection Attacks Against LLM Assistants
ID: 296b7fa5-7a5d-5954-80b8-d3dd4eac7274
STIX ID: report--296b7fa5-7a5d-5954-80b8-d3dd4eac7274
Feed Name: Schneier on Security
This research describes practical "Promptware" prompt-injection attacks against Gemini-powered assistants using indirect vectors (emails, calendar invites, shared documents) to achieve context/memory poisoning, tool misuse, automatic agent/app invocation, and on-device lateral movement; 14 attack scenarios are demonstrated with potential outcomes including data exfiltration, phishing, disinformation, unauthorized streaming, and smart-home control, and Google deployed mitigations after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
