Get all your news in one place.
100's of premium titles.
One app.
Start reading
Geekflare
Geekflare
Keval Vachharajani

Gemini Summaries Can Be Tricked by Hidden Email Prompts

A security researcher has found a prompt injection vulnerability in Google’s Gemini for Workspace that can be exploited through a cleverly crafted email. It was first disclosed via Mozilla’s generative AI bug bounty program, 0din, which shows how attackers can hide instructions inside an email that Gemini follows blindly when asked to summarise the message.

Marco Figueroa, GenAI Bug Bounty Programs Manager at Mozilla, reported the issue, which could be used to trick users into believing their Gmail accounts are compromised. Once the recipient clicks “Summarize this email,” Gemini parses the invisible prompt and appends a fake warning styled as a Google-issued alert urging the user to call a phone number or take other urgent action.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.