Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025
    Facebook X (Twitter) Instagram
    Trending
    • I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better
    • 21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff
    • Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models
    • Ready or Not Regains Flagship Xbox Feature, Play Anywhere
    • Here’s how I stop spam emails from ever reaching my inbox
    • Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers
    • Apple Must Allow Alternative Browser Engines on iOS by December Under Japan’s New Mobile Software Competition Act
    • Samsung Galaxy Buds 3 Series Update Adds Google Gemini Support on Phones Running One UI 8
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Software»Gemini in Gmail Vulnerable to Prompt Injection-Based Phishing Attacks, Researcher Finds
    Software

    Gemini in Gmail Vulnerable to Prompt Injection-Based Phishing Attacks, Researcher Finds

    techupdateadminBy techupdateadminJuly 16, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Gemini in Gmail Vulnerable to Prompt Injection-Based Phishing Attacks, Researcher Finds
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Gemini in Gmail is vulnerable to prompt injection-based phishing attacks, a researcher demonstrated. As per the researcher, the artificial intelligence (AI) chatbot that offers features such as email summary generation and email rewriting can be manipulated into displaying phishing messages to users. This vulnerability poses a significant risk, as attackers could potentially exploit it to conduct online scams. Meanwhile, the Mountain View-based tech giant has reportedly said that it has so far not seen this manipulation technique used against users.

    Researcher Claims Gemini in Gmail Is Vulnerable to Prompt Injection

    The vulnerability was spotted and demonstrated by researcher Marco Figueroa, GenAI Bug Bounty Programmes Manager at Mozilla, via Mozilla’s bug bounty programme for AI tools, 0din. Interestingly, to trigger this vulnerability, the scammer does not have to pull off any high-profile cyber heist. Instead, it can be carried out with a simple text command using a technique known as prompt injection.

    Prompt injection is a type of attack on AI chatbots where an attacker deliberately manipulates the input or prompt to make the model behave in unintended or malicious ways. In this particular scenario, the researcher used indirect prompt injection, where the malicious prompt is embedded inside a document, email, or a web page.

    As per the researcher, he simply wrote a long email and added some hidden text at the end, which contained the prompt injection. The email did not contain any URLs or attachments, which made it easier to reach the receiver’s primary inbox.

    Adding a hidden malicious message in email
    Photo Credit: 0din/Marco Figueroa

     

    As shown in the image, the attacker used a white colour font on a white page to write the malicious message. This text is normally invisible to the receiver of the email. Other ways to add hidden text include using a zero font size, off-screen text placement, and other HTML or CSS tricks.

    Now, if the receiver uses Gemini’s “summarise email” feature, the chatbot will process the hidden text and carry out the command, without the user ever finding out, Figueroa said. He also highlighted that the probability of the chatbot following the command increases if the message is wrapped inside an admin tag, as it considers it a high-priority request.

    gemini hack2 0din Gemini in Gmail vulnerability

    Gemini verbatim repeats the malicious message in the summary
    Photo Credit: 0din/Marco Figueroa

     

    The cybersecurity researcher showed in another screenshot that Gemini indeed carried out the malicious message and displayed it as part of its email summary. Since the message is now coming from Gemini, instead of an email from a likely stranger, the victim could be more likely to believe it and follow the instructions, falling for the scam.

    BleepingComputer reached out to Google to ask about the vulnerability, and a spokesperson said that the company has seen no evidence of similar manipulation so far. Additionally, it was also highlighted that Google is in the process of implementing some mitigations for prompt injection-based adversarial attacks.

    Attacks finds Gemini Gmail InjectionBased phishing Prompt Researcher vulnerable
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Best Laptop I’ve Found for Travel Is $200 Off Right Now
    Next Article Vivo T4R 5G Confirmed to Launch in India Soon; Design Teased
    techupdateadmin
    • Website

    Related Posts

    Software

    Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers

    August 8, 2025
    Gadgets

    Samsung Galaxy Buds 3 Series Update Adds Google Gemini Support on Phones Running One UI 8

    August 8, 2025
    Software

    Herman Miller’s surprise sale slashes prices by 25% – and these are the office chair deals I’d buy for your home and office

    August 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.