Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data
ID: 6aa3c5ff-6659-5354-b152-c5ad09c9ec11
STIX ID: report--6aa3c5ff-6659-5354-b152-c5ad09c9ec11
Feed Name: Infosecurity Magazine (News)
Noma Security discovered and disclosed a zero-click indirect prompt-injection vulnerability dubbed 'GeminiJack' in Google Gemini Enterprise and Vertex AI Search that allowed attackers to embed hidden instructions in shared Google Workspace content (Docs, Calendar, Gmail) to make the AI search for sensitive terms and exfiltrate results via attacker-controlled image URLs; Google patched the issue by changing Gemini/Vertex interactions and separating RAG workflows, but researchers warn that AI assistants with broad data access expand the blast radius for similar indirect prompt-injection attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
