Researchers demonstrated vulnerabilities in Google's Gemini AI, exploiting indirect prompt injections to manipulate smart home devices and trigger malicious actions. By crafting deceptive prompts within calendar invites and leveraging delayed automatic tool invocation, they achieved actions like opening windows, sending abusive messages, and initiating Zoom calls. These attacks, requiring minimal technical skill, highlight the serious risks of prompt injection in AI systems, particularly concerning unintended physical world consequences.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments