YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0075

Incident record

Google Gemini tricked into leaking private meeting data via poisoned calendar invites

Severity
High
Status
Proof-of-concept
Type
Prompt Injection
Target
Google Gemini
Actor
researcher

What happened

Miggo Security disclosed an indirect prompt-injection flaw in Google Gemini in which hidden instructions placed in a calendar event description could override Google Calendar's privacy controls. The payload lay dormant until the victim asked Gemini a routine question about their schedule, at which point the assistant could be steered into summarising private meetings into a new calendar entry the attacker could read. The victim never had to open, accept or click anything from the attacker; an invite landing on the calendar was enough. Google addressed the issue after responsible disclosure.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026