HomeSecurityGoogle Gemini Vulnerability: Private Calendar Data Exposure

Google Gemini Vulnerability: Private Calendar Data Exposure

Cybersecurity researchers have revealed details of a security vulnerability that exploits indirect prompt injection, targeting Google Gemini as a means to bypass authorization mechanisms and use Google Calendar as a data extraction mechanism.

See also: What we can expect from the new Siri with Gemini

Google Gemini vulnerability
Google Gemini Vulnerability: Private Calendar Data Exposure

The vulnerability, explained Miggo Securitylead Liad Eliyahu, made it possible to bypass Google Calendar's privacy controls by hiding a dormant malicious payload inside a standard calendar invitation. This bypass allowed unauthorized access to private meeting data and the creation of misleading calendar events without any direct user interaction.

The attack begins with a new calendar event created by the malicious actor and sent to a target. The invitation description embeds a natural language prompt designed to manipulate the AI, leading to prompt injection. The attack is triggered when a user asks Gemini a seemingly innocent question about their program, causing the AI ​​chatbot to parse the specially crafted prompt in the event description.

This results in summarizing all of the user's meetings for a specific day, adding that data to a new Google Calendar event, and returning a harmless response to the user.

See also: Personal Intelligence: Connecting Gmail, Google Photos, Search with Gemini

Google Gemini Vulnerability: Private Calendar Data Exposure

However, in the background, Gemini creates a new calendar event and writes a full summary of the target user's private meetings to the event description. In many corporate calendar configurations, the new event is visible to the attacker, allowing them to read the extracted private data without any action from the target user.

Although the issue has been addressed after responsible disclosure, the findings show that AI capabilities can broaden the attack surface and inadvertently introduce new security risks as more organizations use AI tools or build their own agents internally to automate workflows. Eliyahu noted that AI applications can be manipulated through the very language they are designed to understand, indicating that vulnerabilities now exist in the language, context, and behavior of AI at runtime.

The revelation comes shortly after Varonis reported on an attack called Reprompt that could allow hackers to extract sensitive data from AI chatbots like Microsoft Copilot with a single click, bypassing enterprise security controls.

See also: Apple will improve Gemini without Google branding on Siri

Google Gemini Vulnerability: Private Calendar Data Exposure

The findings highlight the need for continuous evaluation of large language models (LLMs) on key security dimensions, testing their propensity for misinformation, factual accuracy, bias, harm, and jailbreak resistance, while also securing AI systems from traditional issues.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS