New Delhi: Google’s Gemini AI assistant can be manipulated to control smart home devices easily without the users realising it. The Cybersecurity researchers have successfully demonstrated this, as first reported by Wired, the exploit used a method called as indirect prompt injection, embedded within Google’s Calendar invites. When the users asked the Gemini to summarise their calendar and responded with the simple thank you, the malicious prompt triggered hidden instructions. These commands were then interpreted by Google’s Home AI agent, leading to actions like opening windows or turning off lights.
The vulnerability was disclosed to Google in February, ahead of a live demonstration at the Black Hat cybersecurity conference. Andy Wen, senior director of security product management for Google Workspace, acknowledged this issue in a conversation with Wired. Now the main question is, it is easy for any of the researchers and coders to hack the Google Gemini for their illegal usage, and there will be a question that many of the users will ask.
Andy Wen real world prompt injection attacks are still exceedingly rare, but the admitted they are hard to defend against, given the growing complexity of large language models, It is going to be with the users for a while, he stated, adding that the Google has taken the findings extremely seriously and is accelerating efforts to develop stronger defenses.









