Gemini AI assistant tricked into leaking Google Calendar data
ID: 9e902b19-1772-559b-95a4-bf513ae6ff23
STIX ID: report--9e902b19-1772-559b-95a4-bf513ae6ff23
Feed Name: Bleeping Computer
Researchers at Miggo Security demonstrated a prompt‑injection technique where an attacker embeds natural‑language instructions in a Google Calendar event description; when a user asks Gemini about their schedule, the assistant may obey the injected instructions and create a new event containing summaries of private meetings, potentially leaking sensitive Calendar data to the attacker. The technique bypassed some prior defenses because the instructions appeared benign; Miggo disclosed the findings to Google, which implemented mitigations, and the report highlights the need for context‑aware defenses against semantic attacks on LLM-driven applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
