logo

When Language Becomes the Attack Surface: Inside the Google Gemini Calendar Exploit

ID: 1501a5ba-6e44-5957-a95c-edcc0837a213

STIX ID: report--1501a5ba-6e44-5957-a95c-edcc0837a213

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Miggo Security disclosed a novel indirect prompt-injection vulnerability in Google Gemini’s Google Calendar integration: attackers can embed natural-language instructions inside a calendar event description that remain dormant until Gemini processes calendar data, at which point Gemini can be induced to summarize private meetings into a newly created event whose description is visible to the attacker—enabling silent data exfiltration without exploiting credentials, links, or code and evading traditional syntactic defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.