Google Gemini vulnerability enables hidden phishing attacks
Score: 74/100
4 articles
100.0% coherence
1 day ago
Activity Timeline
Google Gemini flaw hijacks email summaries for phi...
BleepingComputer
Jul 13
14:38
Google Gemini for Workspace vulnerable to prompt i...
IT News Security
Jul 13
21:10
Google Gemini-Lücke ermöglicht versteckte Phishing...
CSO Online
Jul 14
14:34
Google Gemini vulnerability enables hidden phishin...
CSO Online
Primary Article
Jul 16
03:42
Primary Article
CSO Online 16 hours ago
A bug in Google Gemini allows attackers to hijack email summaries and launch phishing attacks.
Google Gemini for Workspace can be abused to generate email summaries that appear legitimate but contain malicious instructions or warnings. The problem is that attackers can redirect their victims to phishing sites without attachments or direct links. The vulnerability was submitted to 0DIN (0Day Investigative Network), Mozilla’s GenAI bug bounty program.
Although similar indirect prompt attacks on Gemini were already reported in 2024 and security measures were taken, the technique is still viable today, according to the expert.
How the attack works
In ablog post, GenAI bug bounty technical product manager Marco Figueroa explains that the attack relies on crafted HTML / CSS inside the email body. Because the injected text is hidden the user never sees the instruction in the original message. The trigger happens when the user requests Gemini to summarize their unread emails, they receive a ma...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock AI Insights
Get AI-generated executive, technical, and remediation briefs with Pro.
Ein Bug in Google Gemini erlaubt es Angreifern, E-Mail-Zusammenfassungen zu kapern und Phishing-Attacken zu starten.
Sadi-Santos – shutterstock.com
Google Gemini für Workspace kann missbraucht werden,...
Google Gemini flaw hijacks email summaries for phishing
Bill Toulas
July 13, 2025
10:38 AM
2
Google Gemini for Workspace can be exploited to generate email summaries that appear legitimate but include...
News
Technology
Security
Google Gemini for Workspace vulnerable to prompt injection attacks
"The new email macros."
Google's Gemini artificial intelligence bundled with the tech giant's Workspace prod...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.