logo

Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data

ID: 6aa3c5ff-6659-5354-b152-c5ad09c9ec11

STIX ID: report--6aa3c5ff-6659-5354-b152-c5ad09c9ec11

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2025-12-10

Date Updated: 2026-04-22

...
...

Noma Security discovered and disclosed a zero-click indirect prompt-injection vulnerability dubbed 'GeminiJack' in Google Gemini Enterprise and Vertex AI Search that allowed attackers to embed hidden instructions in shared Google Workspace content (Docs, Calendar, Gmail) to make the AI search for sensitive terms and exfiltrate results via attacker-controlled image URLs; Google patched the issue by changing Gemini/Vertex interactions and separating RAG workflows, but researchers warn that AI assistants with broad data access expand the blast radius for similar indirect prompt-injection attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.