Invitation Is All You Need! Invoking Gemini for Workspace Agents with a Google Calendar Invite

No ratings

Presented at CODE BLUE 2025 by

Over the past two years, a new class of attacks known as Promptware has emerged, exploiting LLMs at inference time via crafted prompts. Though often dismissed as impractical or exotic, this talk will shatter that misconception forever. We introduce Targeted Promptware Attacks, where an attacker invites a victim to a Google Calendar meeting containing an indirect prompt injection. This hijacks Gemini’s integrated agents, on web, mobile, and Google Assistant-which operate with OS-level Android permissions. We demonstrate 15 real-world exploits, including spamming, phishing, data exfiltration, calendar deletion, device control (e.g., boiler, lights, windows), video streaming a victim via Zoom, and geolocating the victim. These attacks show Promptware’s ability to move laterally across agents and devices, leading to physical-world consequences. Using our threat assessment framework, we find that 73% of identified risks are high-critical, calling for immediate mitigations.