logo

Malicious Google Calendar invites could expose private data

ID: e6f5111f-0028-5427-9c3e-732bbc12fa80

STIX ID: report--e6f5111f-0028-5427-9c3e-732bbc12fa80

Feed Name: Malwarebytes Blog

Threat Score
55/100

Date Published: 2026-01-21

Date Updated: 2026-04-28

...
...

Researchers demonstrated a prompt‑injection attack that weaponizes Google Calendar invites to bypass Gemini's privacy controls: a malicious event description instructs Gemini to create a new event containing synthesized summaries of the victim's meetings (titles, attendees, locations, notes), which an attacker can then read. The specific issue has been reportedly fixed, but the report warns the broader risk of AI assistants treating user-supplied text as high‑priority instructions and provides mitigation advice (decline unknown invites, disable auto-add, avoid sensitive details in events, and tighten domain calendar sharing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.