Google Gemini vulnerability enables hidden phishing attacks

Google Gemini vulnerability enables hidden phishing attacks
A bug in Google Gemini allows attackers to hijack email summaries and launch phishing attacks. Google Gemini for Workspace can be abused to generate email summaries that appear legitimate but contain malicious instructions or warnings. The problem is that attackers can redirect their victims to phishing sites without attachments or direct links. The vulnerability was submitted to 0DIN (0Day Investigative Network), Mozilla’s GenAI bug bounty program. Although similar indirect prompt attacks on Ge...

Save to Folder

Choose a folder to save this article: