A sophisticated method of exploiting Google's AI assistant Gemini through seemingly innocent Calendar and email invitations has been recently discovered.
See also: Google Gemini: How email summaries lead to phishing attacks?

The attack, called Targeted Promptware Attacks, demonstrates how indirect prompt injection can compromise digital privacy and even control physical devices in their homes.
The research reveals that 73% of identified threats pose high to critical risks, allowing attackers to steal emails, track users' locations, broadcast video calls without their consent, and manipulate connected home devices, including lights, windows, and heating systems.
According to researchers from Tel Aviv University, the Technion, and SafeBreach, the exploitation technique relies on embedding malicious prompts within seemingly legitimate Google calendar invitations or Gmail messages.
When users ask their Gemini-powered assistant about emails or calendar events, the exploit triggers context poisoning that compromises the AI's behavior. The researchers identified five distinct categories of attacks: Short-term Context Poisoning, Permanent Memory Poisoning, Tool Misuse, Automatic Agent Invocation , and Automatic App Invocation.
The attack methodology involves complex tool commands (tool_code) embedded in calendar event titles. These commands exploit Gemini's architecture, triggering automatic actions when users use common phrases such as "thank you" or "thank you very much" in their interactions.
See also: Gemini's new icon is rolling out to beta testers
The Utilities Agent becomes particularly vulnerable, allowing attackers to launch applications remotely and exploit their permissions for data extraction.

Most worrying is the research’s demonstration of lateral movement within the device, where the breach extends beyond the AI assistant to control other connected apps and smart home devices.
Attackers can activate home automation systems using commands such as generic_google_home.run_auto_phrase(“Hey Google, Turn on the 'burner'”), potentially creating dangerous physical situations.
The vulnerability also allows unauthorized video streaming via Zoom, automatically launching meeting URLs, and tracking geographic locations via malicious browser redirects. Researchers successfully demonstrated email subject extraction by exploiting Gemini's response templates to include source URLs that transmit sensitive information to attacker-controlled servers.
This Promptware attack path represents a significant evolution in AI security threats, bridging the digital and physical domains through complex prompt manipulation techniques.
See also: Gemini finally inherits a beloved feature
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Google has acknowledged the findings and implemented specific metrics following the researchers’ responsible disclosure. This research highlights the urgent need for robust security in AI-powered assistant applications, as the integration of large language models with IoT devices and access to personal data creates unprecedented attack surfaces that extend far beyond traditional cybersecurity boundaries.
