id: PIR-2026-0032title: Hidden "promptware" in a Google Calendar invite coerces Gemini for Workspace into digital and physical-world actions (data exfiltration, home-device control) when the user asks Gemini to summarize their scheduledate_occurred: not applicable - vulnerability demonstrationdate_detected: 2025-02 (disclosed to Google February 2025)date_disclosed: 2025-08 (Black Hat USA; arXiv 2508.12175); vendor blog "Invitation Is All You Need"status: corroborated (arXiv paper + SafeBreach blog + Google statement + independent coverage)agent_description: Google Gemini for Workspace (web, mobile, and Google Assistant surfaces) with connected agents controlling Google Home / smart devices, Zoom, and location/Workspace data.operator_type: enterprise (Google-operated) serving individual/enterprise usersautonomy_level: autonomous-within-policy (Gemini can invoke connected agents that control physical devices and Workspace actions once triggered by the injected content)model_stack: Google Gemini (Workspace deployment; versions not disclosed)harness: Gemini for Workspace agent integrations + Google Home / smart-device connectorsauthority_scope: data access (Workspace content, location), physical systems (boiler, windows/shutters, lights), external comms (spam/phishing sending, Zoom video streaming)funds_at_risk_usd: unknown (safety and confidentiality incident, not a funds-moving agent)blast_radius: customers/third parties (any Gemini for Workspace user targeted with a crafted invite); potential physical harm in the victim's homefailure_locus: harness (Gemini's Workspace agent integration ingesting untrusted calendar/email content and invoking connected agents)root_cause: prompt-injection (primary; indirect, via calendar-invite / email / document content - "promptware")mechanism: A Calendar invite's title/body carries hidden instructions ("Targeted Promptware"). When the user later asks Gemini to summarize upcoming events, Gemini ingests the invite and treats the embedded instructions as user intent, executing them - including invoking connected agents. Researchers demonstrated 14 attack scenarios across five threat classes (short-term context poisoning, permanent memory poisoning, tool misuse, automatic agent invocation, automatic app invocation): spam, phishing, disinformation, data exfiltration, calendar manipulation, and physical actions (turning on a boiler, opening windows/shutters, controlling lights, streaming the victim over Zoom, geolocation).adversary_present: yes (attacker sends the crafted invite; here, researchers)exploitation_status: researcher-demonstrated (SafeBreach + academic team against production Gemini for Workspace; fixed before any in-wild exploitation per Google)severity: near-miss (full digital + physical exploit chain proven against production; no realized third-party loss)direct_loss_usd: 0indirect_loss_usd: unknowndowntime: nonedata_exposure: none realized; capability included Workspace data, location, live Zoom video, and physical device statedetected_by: third-party (SafeBreach Labs + academic researchers Ben Nassi, Stav Cohen, Or Yair)time_to_detect: not applicable (proactive research)time_to_recover: ~months from disclosure (Feb 2025) to layered mitigations (deployed before Black Hat presentation)remediation: Google deployed a multi-layer mitigation approach - expanded user confirmations for sensitive actions, URL sanitization and trust-level policies, and AI content classifiers to detect suspicious promptsstructural_fix: layered prompt-injection defenses across Gemini for Workspace (confirmation gates on sensitive/physical actions, classifier + URL trust policies)controls_that_worked: prior to the fix, none bounded the chain; post-fix, the added user-confirmation gate on sensitive/physical actions is the control now bounding the physical-world blast radius. Google (Andy Wen) stated the fix was deployed before the issue could be exploited in the wild.telemetry_grade: none/vendor-attested - "fixed before in-wild exploitation" rests on Google's statement; the research chain is documented in an arXiv paper and vendor blog.sources:Independence: strong - academic paper + vendor blog + independent trade press; the "no in-wild exploitation" claim is single-source (Google).
- confidence: high on mechanism, disclosure timing, and demonstrated capabilities; medium on the no-exploitation claim (vendor attestation)
prompt-injection, harness failure_locus, near-miss + researcher-demonstrated.