# PIR-2026-0032 - "Invitation Is All You Need": calendar-invite injection hijacks Gemini and smart-home devices

- `id`: PIR-2026-0032
- `title`: Hidden "promptware" in a Google Calendar invite coerces Gemini for Workspace into digital and physical-world actions (data exfiltration, home-device control) when the user asks Gemini to summarize their schedule
- `date_occurred`: not applicable - vulnerability demonstration
- `date_detected`: 2025-02 (disclosed to Google February 2025)
- `date_disclosed`: 2025-08 (Black Hat USA; arXiv 2508.12175); vendor blog "Invitation Is All You Need"
- `status`: corroborated (arXiv paper + SafeBreach blog + Google statement + independent coverage)

### The agent
- `agent_description`: Google Gemini for Workspace (web, mobile, and Google Assistant surfaces) with connected agents controlling Google Home / smart devices, Zoom, and location/Workspace data.
- `operator_type`: enterprise (Google-operated) serving individual/enterprise users
- `autonomy_level`: autonomous-within-policy (Gemini can invoke connected agents that control physical devices and Workspace actions once triggered by the injected content)
- `model_stack`: Google Gemini (Workspace deployment; versions not disclosed)
- `harness`: Gemini for Workspace agent integrations + Google Home / smart-device connectors

### Authority
- `authority_scope`: data access (Workspace content, location), physical systems (boiler, windows/shutters, lights), external comms (spam/phishing sending, Zoom video streaming)
- `funds_at_risk_usd`: unknown (safety and confidentiality incident, not a funds-moving agent)
- `blast_radius`: customers/third parties (any Gemini for Workspace user targeted with a crafted invite); potential physical harm in the victim's home
- `failure_locus`: harness (Gemini's Workspace agent integration ingesting untrusted calendar/email content and invoking connected agents)

### The failure
- `root_cause`: prompt-injection (primary; indirect, via calendar-invite / email / document content - "promptware")
- `mechanism`: A Calendar invite's title/body carries hidden instructions ("Targeted Promptware"). When the user later asks Gemini to summarize upcoming events, Gemini ingests the invite and treats the embedded instructions as user intent, executing them - including invoking connected agents. Researchers demonstrated 14 attack scenarios across five threat classes (short-term context poisoning, permanent memory poisoning, tool misuse, automatic agent invocation, automatic app invocation): spam, phishing, disinformation, data exfiltration, calendar manipulation, and physical actions (turning on a boiler, opening windows/shutters, controlling lights, streaming the victim over Zoom, geolocation).
- `adversary_present`: yes (attacker sends the crafted invite; here, researchers)
- `exploitation_status`: researcher-demonstrated (SafeBreach + academic team against production Gemini for Workspace; fixed before any in-wild exploitation per Google)

### Impact
- `severity`: near-miss (full digital + physical exploit chain proven against production; no realized third-party loss)
- `direct_loss_usd`: 0
- `indirect_loss_usd`: unknown
- `downtime`: none
- `data_exposure`: none realized; capability included Workspace data, location, live Zoom video, and physical device state

### Detection and recovery
- `detected_by`: third-party (SafeBreach Labs + academic researchers Ben Nassi, Stav Cohen, Or Yair)
- `time_to_detect`: not applicable (proactive research)
- `time_to_recover`: ~months from disclosure (Feb 2025) to layered mitigations (deployed before Black Hat presentation)
- `remediation`: Google deployed a multi-layer mitigation approach - expanded user confirmations for sensitive actions, URL sanitization and trust-level policies, and AI content classifiers to detect suspicious prompts
- `structural_fix`: layered prompt-injection defenses across Gemini for Workspace (confirmation gates on sensitive/physical actions, classifier + URL trust policies)
- `controls_that_worked`: prior to the fix, none bounded the chain; post-fix, the added user-confirmation gate on sensitive/physical actions is the control now bounding the physical-world blast radius. Google (Andy Wen) stated the fix was deployed before the issue could be exploited in the wild.

### Evidence
- `telemetry_grade`: none/vendor-attested - "fixed before in-wild exploitation" rests on Google's statement; the research chain is documented in an arXiv paper and vendor blog.
- `sources`:
  - https://arxiv.org/abs/2508.12175
  - https://www.safebreach.com/blog/invitation-is-all-you-need-hacking-gemini/
  - https://sites.google.com/view/invitation-is-all-you-need/home
  - https://www.techrepublic.com/article/news-google-gemini-indirect-prompt-injection-attack/
  - https://www.bleepingcomputer.com/news/security/google-calendar-invites-let-researchers-hijack-gemini-to-leak-user-data/
  - `independence`: strong - academic paper + vendor blog + independent trade press; the "no in-wild exploitation" claim is single-source (Google).
- `confidence`: high on mechanism, disclosure timing, and demonstrated capabilities; medium on the no-exploitation claim (vendor attestation)

### Verification notes
- CORRECTION: candidate intake said "demonstrated 15 exploits." The primary source (arXiv 2508.12175 and SafeBreach) states 14 attack scenarios across five threat classes. Corrected to 14. The count is the only material error; all demonstrated capabilities (boiler, windows/shutters, lights, Zoom streaming, geolocation) are confirmed.
- Disclosure to Google February 2025 and Black Hat USA August 2025 (presented Aug 6) confirmed. Researcher attribution: Ben Nassi, Stav Cohen, Or Yair (SafeBreach + academic; candidate's "SafeBreach + Tel Aviv Univ." is approximately right - the team spans SafeBreach and academia).
- Classification holds: `prompt-injection`, harness failure_locus, near-miss + `researcher-demonstrated`.
