Tools AI Risk Radar ai-incident-0075
Incident record
Google Gemini tricked into leaking private meeting data via poisoned calendar invites
- Severity
- High
- Status
- Proof-of-concept
- Type
- Prompt Injection
- Target
- Google Gemini
- Actor
- researcher
What happened
Miggo Security disclosed an indirect prompt-injection flaw in Google Gemini in which hidden instructions placed in a calendar event description could override Google Calendar's privacy controls. The payload lay dormant until the victim asked Gemini a routine question about their schedule, at which point the assistant could be steered into summarising private meetings into a new calendar entry the attacker could read. The victim never had to open, accept or click anything from the attacker; an invite landing on the calendar was enough. Google addressed the issue after responsible disclosure.
Sources
- Miggo Security: weaponising calendar invites, a semantic attack on Google Gemini (19 January 2026)www.miggo.io/post/weaponizing-calendar-invites-a-semantic-at…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026