
A security researcher has found a prompt injection vulnerability in Google’s Gemini for Workspace that can be exploited through a cleverly crafted email. It was first disclosed via Mozilla’s generative AI bug bounty program, 0din, which shows how attackers can hide instructions inside an email that Gemini follows blindly when asked to summarise the message.
Marco Figueroa, GenAI Bug Bounty Programs Manager at Mozilla, reported the issue, which could be used to trick users into believing their Gmail accounts are compromised. Once the recipient clicks “Summarize this email,” Gemini parses the invisible prompt and appends a fake warning styled as a Google-issued alert urging the user to call a phone number or take other urgent action.