Trending Topics

GeminiJack zero-click vulnerability exposes dangerous underbelly of the AI revolution
Just weeks after Google Chief Executive Sundar Pichai told the BBC that AI models were “prone to errors” and people should not “blindly trust everything they say,” the tech giant’s own business AI flagship was found vulnerable to a zero-click exploit. Turns out that Gemini Enterprise could enable an attacker to hide malicious instructions in emails, calendar invites and shared documents.
GeminiJack, as the vulnerability has been labelled, was discovered by Noma, whose own platform claims to “secure and govern your AI and Agents,” and made public by Security research lead, Sasi Levi.
GeminiJack made it possible for a threat actor to “steal sensitive corporate information by embedding hidden instructions inside a shared or externally contributed document,” Levi confirmed.
Example of GeminiJack attack
The given example was shockingly worrying. That attacker could share a Google Doc that included indirect prompt injection about budgets, without notification. Any employee who later searched Gemini Enterprise for budgets would then trigger the AI to “automatically retrieve the poisoned document and execute the instructions”.
The results of the attack were then sent to the attacker by way of an external image request, of all things. “Specific to the GeminiJack findings,” Levi told me, “Google didn’t filter HTML output, which means an embedded image tag triggered a remote call to the attacker’s server when loading the image.
“The URL contains the exfiltrated internal data discovered during searches.”
The big point being that this flagged no warnings, required no clicks. Just that document, email or calendar invite being shared.
How can you fight GeminiJack and similar AI attacks?
“Incidents like GeminiJack show that prompt injection and data leakage are no longer edge-case research topics,” James Wickett, CEO of DryRun Security, told TechFinitive.
“They are symptoms of a deeper architectural problem in how enterprises are wiring LLMs into their systems, even at the biggest companies.”
Although Google has already deployed updates to fix the vulnerability, it doesn’t change the fact that AI has, in effect, become another access layer to the enterprise. And one that is widely misunderstood in terms of security and privacy impacts.
“GeminiJack is a great example of the greatly expanded attack surface that AI systems present,” said James Maude, Field CTO at BeyondTrust.
He added that the malicious commands involved “are not executable code or scripts containing malware, the things that traditional security controls scan for”.
End result: layers of defence bypassed. Period.
Elad Luz, Head of Research at Oasis Security, recommended that organisations must now review which data sources are connected, bearing in mind that both native Google data sources and external integrations may be included.
“In general,” Luz wisely concluded, “agents should be granted access to data and tools only when needed, for a limited duration, based on clear business justification, and with full auditing.”
More articles by security expert Davey Winder
- ShadyPanda played the long game, waiting years to infect 4 million browsers with spyware
- Use ASUS routers or computers? Get these updates now as critical vulnerabilities confirmed
- Latest Have I Been Pwned update gives 1.3 billion new reasons to stop relying on passwords
- Internet down — the cloudy lessons from Azure and AWS outages
