Chronicle/Attacks & incidents

Google Bard Workspace extensions could be prompt-injected to leak chat data via rendered images

AttackVulnerability disclosureSignificance assistant-drafted

Researcher Johann Rehberger reported that a shared Google Doc carrying hidden instructions could cause Bard, with Workspace extensions enabled, to render images whose URLs carried conversation data to an attacker endpoint. The researcher reports disclosure on 2023-09-19 and a Google fix on 2023-10-19.

Why it matters

An early case showing that connecting an assistant to email and documents turns shared files into an exfiltration channel.

Key facts

As stated in the sources, with where to find them.

  • Reported to Google 2023-09-19; fixed 2023-10-19 per the researcher's timeline.Disclosure timeline
  • Exfiltration used markdown image rendering pointed at a Google-hosted script endpoint that the content security policy allowed.Main write-up

Findings that cite this record

Key questions this bears on

Sources

Related records