Google Gemini flaw hijacks email summaries for phishing

Google Gemini AI Vulnerability Exploited for Phishing Attacks Using Email Summaries
Photo: BleepingComputer

Google Gemini AI Vulnerability Exploited for Phishing Attacks Using Email Summaries

A recently discovered flaw in Google’s Gemini for Workspace allows attackers to exploit the AI’s email summary feature for phishing. The vulnerability involves inserting invisible, malicious instructions within the body text of an email using HTML and CSS, which are not visible to the recipient. When the recipient asks Gemini to summarize the email, the AI inadvertently follows the hidden directive, generating a message that appears to come from a trusted source. An example attack showed Gemini generating a warning about the user’s Gmail password being compromised, alongside a fake support number. Despite safeguards being implemented since 2024 to block these types of prompt injection attacks, the flaw remains exploitable. Researchers suggest security teams implement filters to neutralize or flag such hidden content. Google has acknowledged the issue and is working on deploying additional mitigations, but has not yet seen evidence of widespread exploitation in the wild.

Leave a Reply

Your email address will not be published. Required fields are marked *