Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home
image via WIRED
August 6, 2025, 1:00 PM
- •Security researchers demonstrated a series of attacks against Google's Gemini AI, including indirect prompt injections that could control smart home devices.
- •The attacks began with poisoned Google Calendar invitations that, when summarized by Gemini, triggered actions like opening windows and turning on appliances.
- •The researchers also developed attacks that could generate malicious content, steal data, and initiate unwanted actions on web and mobile platforms.
- •Google is addressing the vulnerabilities with multiple fixes and is accelerating the rollout of defenses against AI prompt-injection attacks.
- •The researchers emphasize the need for enhanced security in AI development as LLMs become increasingly integrated with physical systems.
Researchers have demonstrated a sophisticated series of attacks against Google's Gemini AI, highlighting vulnerabilities that could have real-world consequences. The attacks, which started with poisoned calendar invitations, allowed the researchers to remotely control smart home devices by exploiting prompt injections. These attacks demonstrate the potential for malicious actors to manipulate AI systems and the urgent need for improved security measures as AI becomes increasingly integrated into our daily lives. Google is responding to the findings and implementing various security enhancements.
Entities Mentioned
Ben NassiStav CohenOr YairAndy WenJohann Rehberger
Topics Covered
SecuritySecurity / Cyberattacks and HacksSecurity / Security NewsBusiness / Artificial Intelligence
Comments (0)
No comments yet.