Hackers have found a new way to manipulate Google’s AI assistant, Gemini, using hidden commands embedded in calendar invites, according to fresh research from Tel Aviv University, Technion, and SafeBreach.
The technique, known as indirect prompt injection, enables attackers to hijack Gemini and control real-world smart home devices — opening window shutters, switching off lights, activating boilers — all triggered by seemingly innocent user interactions.
The attack involves placing malicious instructions hidden inside calendar event descriptions. When a user asks Gemini to summarise their scheduled events, it processes the prompts embedded in those invites without recognising the risk. Because Gemini pulls context from these calendar events, it can be tricked into executing harmful commands without direct input from the user.
For example, Gemini can be prompted to activate smart home devices when the user replies with everyday words like “thanks” or “great.” According to Wired, these simple responses act as triggers for embedded instructions that Gemini processes as legitimate commands.
Multiple Attack Variants Demonstrated
The researchers developed fourteen different attack scenarios under the project name Invitation Is All You Need!
Beyond controlling smart devices, the team demonstrated how Gemini could be forced to start Zoom calls, send spam messages, read browser content, and even delete calendar events. In one particularly unsettling example, Gemini read abusive messages drawn from a prompt injection intended to shock the user.
Despite the seriousness, Google’s security team stated that such attacks have not yet been observed in the wild, though they acknowledge the potential danger.
This recent discovery is part of a broader pattern of Gemini-related vulnerabilities. Last month, hackers used a social engineering tactic to trick users into calling attacker-controlled phone numbers or visiting suspicious websites. This attack was cleverly disguised as trusted advice from Google, showing the increasing sophistication of threats aimed at Gemini users.
The Growing Threat of “Promptware”
Generative AI systems like Gemini have rapidly proliferated across the technology sector, becoming integral to many everyday applications.
While AI giants regularly discuss safety, the advancing capabilities of these systems have created new malware threats. The researchers describe these as “promptware” – malware embedded in prompts that hijack AI behavior.
The team’s use of calendar invites to manipulate Gemini’s connected Google smart home ecosystem may represent the first instance of an AI attack causing tangible, real-world effects. Gemini’s limited agentic capabilities, such as accessing calendars and controlling Assistant smart home devices, make it an attractive target for malicious actors looking to disrupt users or steal data.
This kind of attack exploits what’s called indirect prompt injection, where malicious instructions are provided to an AI by someone other than the user. It cleverly evades existing safeguards by embedding harmful commands in everyday data – such as calendar appointments – that the AI accesses for context.
This embedded instruction causes Gemini to activate the boiler whenever it detects one of the trigger words from the user. Because the commands are hidden inside seemingly benign calendar entries, Google’s security filters initially failed to detect them.
The research team believes this to be the first documented example of a prompt-injection attack transitioning from purely digital manipulation to physical device control. Besides controlling smart lights, thermostats, and blinds, the researchers showed that the calendar-based attack surface could be used to generate insulting messages, spam users, delete calendar appointments, and even open malicious websites.
This delayed triggering of actions makes it difficult for users to identify the source of the problem. For example, simply saying “thank you” to Gemini – an action that wastes no energy and seems natural – could unknowingly activate multiple hidden malicious commands. There would be no obvious reason for users to suspect a calendar event as the cause.
The findings were presented at the recent Black Hat security conference. The research team responsibly disclosed the vulnerabilities to Google, starting collaboration in February 2025 to develop mitigations.
Recommended reading
- Majority of Companies Already Past AI Agent Experimentation Phase
- Report: AI Agents Are Triggering Business Restructure
- 80% of Firms Say Their AI Agents Have Taken Rogue Actions
Andy Wen from Google told Wired that analysis of this attack “directly accelerated” the rollout of new prompt-injection defenses. Since June, Google has implemented changes designed to detect unsafe instructions embedded in calendar invites, documents, and emails. Additional user confirmations have been introduced for sensitive actions like deleting calendar events.
Security experts have long known that large language models (LLMs) are vulnerable to simple prompt manipulations, such as commands to “ignore previous instructions.” Despite advancements since GPT-3, today’s most sophisticated AI models remain susceptible to attacks, especially agent-based systems connected to real-world devices.
Recent tests have found that every major AI assistant has failed at least one critical security assessment.
Google Responds With New Safeguards
Google first learned of these vulnerabilities in February 2025 and requested a 90-day window to respond. The company has since deployed several safeguards, including:
-
Mandatory user confirmations for sensitive actions
-
Enhanced detection and filtering of suspicious URLs
-
A new classifier to identify indirect prompt injections
Google reports testing all attack scenarios internally, including variants, and confirms these defenses are now active across all Gemini applications.





