Chronicle/Attacks & incidents

SafeBreach shows Google Calendar invites can hijack Gemini for Workspace agents

AttackVulnerability disclosureSignificance assistant-drafted

SafeBreach researchers showed that instructions in calendar invite titles or email subjects, retrieved when a user asked Gemini about their schedule, could trigger tool misuse such as deleting events, opening URLs, exfiltrating email subjects, and controlling connected smart-home devices. They disclosed to Google in February 2025, and Google deployed layered mitigations including confirmations, URL handling policies and injection classifiers.

Why it matters

It extended assistant prompt injection from data leaks to actions on physical devices and apps.

Key facts

As stated in the sources, with where to find them.

  • Affected surfaces: Gemini web, mobile app, and Android voice assistant with Workspace, Google Home and Zoom integrations.Affected products
  • Disclosed to Google February 2025; Google's mitigation response by June 2025.Disclosure timeline

Findings that cite this record

Key questions this bears on

Sources

Related records