13 Sources
[1]
Google Gemini Bug Turns Gmail Summaries into Phishing Attack
If you rely on Google's Gemini chatbot to summarize your incoming emails, be careful: The technology can also be abused to deliver phishing attacks, according to new security research. Gemini can automatically post the summaries in Gmail, giving you a convenient breakdown of all the main points
[2]
Google Gemini flaw hijacks email summaries for phishing
Google Gemini for Workspace can be exploited to generate email summaries that appear legitimate but include malicious instructions or warnings that direct users to phishing sites without using attachments or direct links. Such an attack leverages indirect prompt injections that are hidden inside
[3]
Google Gemini vulnerable to a stupidly easy prompt injection attack in Gmail AI summaries
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. AI first, security later: As GenAI tools make their way into mainstream apps and workflows, serious concerns are mounting about their real-world safety. Far from boosting productivity, these systems
[4]
Gmail AI summaries can be hijacked for phishing scams
Google is trying to shove its "AI" into all of its products at once. You can't use Search, Android, or Chrome without being prompted to try out some flavor of Gemini. But maybe wait a bit before you let Google's large language model summarize your Gmail messages... because apparently it's easy to
[5]
Google Gemini for Workspace has been exploited to send emails with hidden malicious messages
This prompt injection style attack can get around antivirus scans A flaw in Google Gemini for Workspace can be exploited by hackers to insert malicious instructions that could misdirect the AI tool and cause it to direct users to phishing sites. As reported by Bleeping Computer, this
[6]
Google Gemini can be hijacked to display fake email summaries in phishing scams
Businesses should make sure invisible text is not processed by the AI Cybercriminals have found a creative new way to abuse Google's Generative Artificial Intelligence (GenAI) to steal people's Gmail accounts. Google introduced Gemini, its AI-powered chatbot assistant into its Workspace suite of
[7]
This Google Gemini Flaw Can Create Malicious Gmail AI Summaries
AI summaries are meant to make life easier: They're meant to truncate a large amount of text into something you can quickly scan, so you can spend time on more pressing matters. The trouble is, you can't always trust these summaries. Usually, that's because AI hallucinates, and incorrectly
[8]
Hackers hunt your emails with Google Gemini
A prompt-injection vulnerability in Google Gemini for Workspace was disclosed, enabling the generation of seemingly legitimate email summaries that can direct users to phishing sites via hidden instructions. This method circumvents traditional detection by avoiding attachments or direct
[9]
Gemini flaw lets attackers hijack email summaries for phishing - Phandroid
A new flaw in Google Gemini for Workspace could open the door to phishing attacks, using AI-generated email summaries to deceive users. The issue was disclosed through Odin, Mozilla's bug bounty program for generative AI tools. Security researcher Marco Figueroa, who leads Mozilla's GenAI bug
[10]
Gemini in Gmail Can Be Hacked to Send Phishing Messages, Researcher Finds
Gemini is said to treat admin commands with a higher priority Gemini in Gmail is vulnerable to prompt injection-based phishing attacks, a researcher demonstrated. As per the researcher, the artificial intelligence (AI) chatbot that offers features such as email summary generation and email
[11]
Urgent warning for 1.8 billion Gmail users: 'Hidden danger' steals passwords in ways even AI can't detect
A "hidden danger," which is stealing passwords, has prompted Google to issue an urgent warning for more than a billion Gmail users. The new type of attack has been flying under the radar, attacking 1.8 billion Gmail users without them even realizing it. As the danger looms over Gmail accounts,
[12]
Google AI Chatbot Target of Potential Phishing Attacks | PYMNTS.com
At issue is a prompt-injection flaw that allows cybercriminals to design phishing or vishing campaigns by creating messages that appear to be legitimate Google security warnings, the report said. Fraudsters can embed malicious prompt instructions into an email with "admin" instructions. If a
[13]
Gmail users beware! Scammers are using Gemini to steal your password, here's how
Experts urge use of email filters and staff training; Google says it's actively strengthening defences against prompt injection threats. Security experts have discovered a new Gmail scam that exploits Gemini to steal users' data. The AI tool, which integrates directly into Gmail via a vertical
Share
Copy Link
A security flaw in Google Gemini for Workspace allows attackers to manipulate AI-generated email summaries, potentially turning them into phishing tools. This vulnerability highlights the growing concerns about AI safety in mainstream applications.
Researchers have uncovered a significant security flaw in Google Gemini for Workspace, specifically affecting its email summary feature in Gmail. This vulnerability allows attackers to manipulate AI-generated summaries, potentially turning them into sophisticated phishing tools
1
. The discovery was made through Mozilla's bug bounty program for AI services, 0DIN, highlighting the growing concerns about AI safety in mainstream applications2
.
Source: PC Magazine
The attack leverages a technique known as "prompt injection," where hidden instructions are embedded within an email's body text. These instructions are invisible to the user but are processed by Gemini when generating email summaries. Attackers can achieve this by:
3
When a user requests Gemini to summarize the email, the AI faithfully follows the hidden instructions, potentially generating fake security warnings or phishing messages within the summary.
This vulnerability is particularly concerning because:
4

Source: PCWorld
Marco Figueroa, the researcher who disclosed the flaw, described prompt injections as "the new email macros," emphasizing the severity of the threat due to the perceived trustworthiness of AI-generated content
2
.Related Stories
Google has acknowledged the issue and stated that they are actively working on addressing it. The company's response includes:
5
Google also emphasized that they have not seen evidence of this specific method being used in active attacks against users.
Source: TechSpot
To mitigate the risks associated with this vulnerability, experts suggest:
2
As AI technologies continue to be integrated into everyday applications, this incident serves as a reminder of the importance of robust security measures and ongoing vigilance in the face of evolving cyber threats.
Summarized by
Navi
[1]
[2]
[3]