A calendar invite made Gemini open the windows
SafeBreach showed hidden text in an event could trigger real-world actions through Google Home when a user asked for their schedule.
By The Agentic Times ·

Researchers from SafeBreach and Tel Aviv University showed at Black Hat USA in August 2025 that a Google Calendar invitation could hijack Gemini and make it control physical devices in the victim's home. Google said it had fixed the issues before the talk.
The attack placed instructions in the title or description of a calendar event sent to the target. When the user later asked Gemini to summarise their upcoming schedule, the assistant read the event and followed the embedded instructions. In the demonstrations, Gemini opened smart shutters, turned on a boiler, started a video call, sent the user's location and deleted calendar events.
Some of the payloads used a delayed trigger: the instruction told Gemini to act only when the user next said a common word such as "thanks", so that the malicious action was separated from the poisoned content. The researchers called the class of attacks "promptware".
Google said it had rolled out mitigations, including additional user confirmations for sensitive actions and stronger filtering of untrusted content, and credited the researchers for reporting the issues in February.
The work was among the first to demonstrate prompt injection producing physical consequences rather than data leakage. It reinforced a point made repeatedly by researchers in 2025: an assistant that reads calendar invites, emails and documents is reading attacker-controlled input, and every tool connected to it is a potential target.
Sources
- wired.comhttps://www.wired.com/story/google-gemini-calendar-invite-hijack-smart-home/
- safebreach.comhttps://www.safebreach.com/blog/invitation-is-all-you-need-google-gemini-promptware/
