logo

Indirect Prompt Injection Attacks Against LLM Assistants

ID: 296b7fa5-7a5d-5954-80b8-d3dd4eac7274

STIX ID: report--296b7fa5-7a5d-5954-80b8-d3dd4eac7274

Feed Name: Schneier on Security

Threat Score
70/100

Date Published: 2025-09-03

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This research describes practical "Promptware" prompt-injection attacks against Gemini-powered assistants using indirect vectors (emails, calendar invites, shared documents) to achieve context/memory poisoning, tool misuse, automatic agent/app invocation, and on-device lateral movement; 14 attack scenarios are demonstrated with potential outcomes including data exfiltration, phishing, disinformation, unauthorized streaming, and smart-home control, and Google deployed mitigations after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.