Miggo Security reports that instructions in a calendar event description stayed dormant until the user asked Gemini about their schedule, then led Gemini to summarize the user's private meetings into a new event the attacker could view. Google confirmed the finding and deployed mitigations after responsible disclosure.
Why it matters
It shows calendar-borne injection persisted as a vector after the 2025 mitigations for similar attacks.
Key facts
As stated in the sources, with where to find them.
- Exfiltration used a newly created calendar event rather than an external network request.Core vulnerability section
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Nov 20, 2025
Jul 28, 2025
Aug 6, 2025
Aug 6, 2025
Mar 16, 2026
Feb 13, 2026