A Google Gemini security flaw allowed hackers to use calendar invites to steal private data



  • Researchers Discover Rapid Injection of Gemini AI Through Google Calendar Invitations
  • Attackers could leak private meeting data with minimal user interaction
  • The vulnerability has been mitigated, reducing the risk of immediate exploitation.

Security researchers have found another way to run rapid injection attacks on Google’s Gemini AI, this time to leak sensitive data from Google Calendar.

Notice injection is a type of attack in which the malicious actor hides a notice in an otherwise benign message. When the victim tells their AI to analyze the message (or use it as data in their work), the AI ​​ends up executing the message and carrying out the actor’s orders.



Leave a Comment

Your email address will not be published. Required fields are marked *