Researcher Johann Rehberger reported that a shared Google Doc carrying hidden instructions could cause Bard, with Workspace extensions enabled, to render images whose URLs carried conversation data to an attacker endpoint. The researcher reports disclosure on 2023-09-19 and a Google fix on 2023-10-19.
Why it matters
An early case showing that connecting an assistant to email and documents turns shared files into an exfiltration channel.
Key facts
As stated in the sources, with where to find them.
- Reported to Google 2023-09-19; fixed 2023-10-19 per the researcher's timeline.Disclosure timeline
- Exfiltration used markdown image rendering pointed at a Google-hosted script endpoint that the content security policy allowed.Main write-up
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Mar 5, 2024
Mar 24, 2025
Apr 1, 2025
Sep 20, 2024
Aug 6, 2025
Jul 8, 2025