Chronicle/Attacks & incidents

Miggo finds Gemini calendar-invite injection that bypassed privacy controls on meeting data

AttackVulnerability disclosureSignificance assistant-drafted

Miggo Security reports that instructions in a calendar event description stayed dormant until the user asked Gemini about their schedule, then led Gemini to summarize the user's private meetings into a new event the attacker could view. Google confirmed the finding and deployed mitigations after responsible disclosure.

Why it matters

It shows calendar-borne injection persisted as a vector after the 2025 mitigations for similar attacks.

Key facts

As stated in the sources, with where to find them.

  • Exfiltration used a newly created calendar event rather than an external network request.Core vulnerability section

Findings that cite this record

Key questions this bears on

Sources

Related records