SafeBreach researchers showed that instructions in calendar invite titles or email subjects, retrieved when a user asked Gemini about their schedule, could trigger tool misuse such as deleting events, opening URLs, exfiltrating email subjects, and controlling connected smart-home devices. They disclosed to Google in February 2025, and Google deployed layered mitigations including confirmations, URL handling policies and injection classifiers.
Why it matters
It extended assistant prompt injection from data leaks to actions on physical devices and apps.
Key facts
As stated in the sources, with where to find them.
- Affected surfaces: Gemini web, mobile app, and Android voice assistant with Workspace, Google Home and Zoom integrations.Affected products
- Disclosed to Google February 2025; Google's mitigation response by June 2025.Disclosure timeline
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Aug 6, 2025
Jul 28, 2025
Jun 10, 2025
Jan 19, 2026
Aug 1, 2025
Jul 8, 2025