By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Indirect prompt injection in Google Gemini enabled unauthorized access to meeting data – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Indirect prompt injection in Google Gemini enabled unauthorized access to meeting data – News
News

Indirect prompt injection in Google Gemini enabled unauthorized access to meeting data – News

News Room
Last updated: 2026/01/19 at 11:07 AM
News Room Published 19 January 2026
Share
Indirect prompt injection in Google Gemini enabled unauthorized access to meeting data –  News
SHARE

A new report out today from cybersecurity company Miggo Security Ltd. details a now-mitigated vulnerability in Google LLC’s artificial intelligence ecosystem that allowed for a natural-language prompt injection potentially to bypass calendar privacy controls and exfiltrate sensitive meeting data via Google Gemini.

The issue arose from Gemini’s deep integration with Google Calendar, which allows the AI to parse event titles, descriptions, attendees and timing to answer routine user queries such as schedule summaries.

Miggo’s researchers found that by embedding a carefully worded prompt into the description field of a calendar invite, an attacker could plant a dormant instruction that Gemini would later execute when triggered by a normal user request. The attack relied entirely on natural language and no malicious code was required.

The exploit involved three stages. The first stage involves an attacker sending a calendar invite containing a harmful but syntactically benign instruction that directed Gemini to summarize a user’s meetings, create a new calendar event and store that summary in the event description.

In the second stage, the payload remains inactive until the user asks Gemini a routine question about their schedule, causing the assistant to ingest and interpret all relevant calendar entries. The third stage then sees Gemini carrying out the embedded instructions and creating a new event that contained summaries of private meetings.

In some enterprise configurations, that newly created event was visible to the attacker and provided unauthorized access to sensitive data without any direct user interaction.

Miggo’s researchers describe the methodology as a form of indirect prompt injection leading to an authorization bypass. The exploit evaded various defenses to detect malicious prompts because the instructions appeared plausible in isolation and only became dangerous when executed with Gemini’s tool-level permissions.

Google confirmed the findings and has since mitigated the vulnerability.

The researchers argue that while the specific flaw may have been fixed, the incident highlights a broader shift in application security. To protect against such future events, the researchers say that “defenders must evolve beyond keyword blocking.”

“Effective protection will require runtime systems that reason about semantics, attribute intent and track data provenance,” the report concludes. “In other words, it must employ security controls that treat large language models as full application layers with privileges that must be carefully governed.”

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article CAKE_MQ Slated For Linux 7.0 To Adapt SCH_CAKE For Today’s Multi-Core World CAKE_MQ Slated For Linux 7.0 To Adapt SCH_CAKE For Today’s Multi-Core World
Next Article Why Are Android Phones Getting Rid Of SIM Cards? – BGR Why Are Android Phones Getting Rid Of SIM Cards? – BGR
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Should You Unplug Your Computer When Going On Vacation? – BGR
Should You Unplug Your Computer When Going On Vacation? – BGR
News
Final Calm Before the Big Shift: BlockDAG’s alt=
Final Calm Before the Big Shift: BlockDAG’s $0.001 Pricing Signals a Crucial Moment in Its Crypto Presale
Gadget
How Shell Foundation and 500 Global structure risk in African climate tech
How Shell Foundation and 500 Global structure risk in African climate tech
Computing
Quick Share is crashing on Android 16 QPR3 Beta 2; are you affected?
Quick Share is crashing on Android 16 QPR3 Beta 2; are you affected?
News

You Might also Like

Should You Unplug Your Computer When Going On Vacation? – BGR
News

Should You Unplug Your Computer When Going On Vacation? – BGR

4 Min Read
Quick Share is crashing on Android 16 QPR3 Beta 2; are you affected?
News

Quick Share is crashing on Android 16 QPR3 Beta 2; are you affected?

3 Min Read
I tested the best US pizza makers costing 9 to ,800. Here’s what was worth the price
News

I tested the best US pizza makers costing $129 to $2,800. Here’s what was worth the price

19 Min Read
Navy tests robot war helicopter that flies itself on ‘anti-submarine’ missions
News

Navy tests robot war helicopter that flies itself on ‘anti-submarine’ missions

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?