Google's AI could be tricked into enabling spam, revealing a user's location, and leaking private correspondence with a calendar invite — 'promptware' targets LLM interface to trigger malicious activity

The Google logo on a background of circles
(Image credit: Google, Malte Luk)

SafeBreach researchers have revealed how a malicious Google Calendar invite could be used to exploit Gemini—the AI assistant that Google has built into its Workplace software suite, Android operating system, and search engine—as part of their ongoing efforts to determine the dangers posed by the rapid integration of AI in tech products.

The researchers dubbed an exploit like this "promptware" because it "utilizes a prompt—a piece of input via text, images, or audio samples—that is engineered to exploit an LLM interface at inference time to trigger malicious activity, like spreading spam or extracting confidential information." The broader security community has underestimated the risks associated with promptware, SafeBreach said, and this report is meant to demonstrate just how much havoc these exploits can wreak.

Latest Videos FromTom's Hardware
TOPICS
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • FoxTread3
    Admin said:
    Google's AI could be tricked into enabling spam, revealing a user's location, and leaking private correspondence, among other things, with just a calendar invite.

    Google's AI could be tricked into enabling spam, revealing a user's location, and leaking private correspondence with a calendar invite — 'promptwa... : Read more
    August 12, 2025 - This really concerns me and brings me back to my forever rant about the headlong dash of the Tech industry, followed closely and trustingly by big business and a naive public. Phone apps so that we don't have carry ugh.. dirty cash, smart appliances and lighting that use phone apps just to work, key cards for opening home and office doors.. which won't work when the electricity goes out. Think Manhattan, New York when they had a huge storm knock out the power, and people couldn't get in and out of buildings with electronic card locks. Finally, there are my least favorites. "Syncing" everything so that when one account is hacked, they are all hacked like falling dominos, and "auto pay". My ISP charges me $10+ monthly on my bill because I won't use auto pay, but where hacked and lost 100,000 customers info. The Tech industry keeps inventing "doors" that need locks for no apparent reason, and there are plenty of very smart criminals ready and willing to break those locks. Sticking AI into everything before it is fully mature, and has adequate security measures in place. Seems to me to be this side of insane. Lastly, none of the companies take any responsibility when their systems are hacked. They just shrug and kind of say.. "Our bad.. here's a way to check and see how much of your financial information we have put at risk... but we won't give you compensation of any kind."
    Reply