Google Gemini’s Hilarious Slip-Up: Invisible Phishing Messages in Plain Sight!
Marco Figueroa discovered that Google Gemini for Workspace has a prompt injection vulnerability. By sending an email with hidden phishing text, attackers can trick Gemini into displaying harmful messages. Google has not yet confirmed if they have fixed this weakness, but they have been working on mitigating such prompt injection attacks.

Hot Take:
Looks like Google’s Gemini assistant has been caught with its digital pants down, falling victim to some good ol’ fashioned trickery. Who knew that AI could be so easily duped with a bit of invisible ink? But hey, even robots need to watch out for phishing scams these days! Time to teach these digital assistants to read between the lines… or maybe just the lines they can see.
Key Points:
- Google Gemini for Workspace has a prompt injection vulnerability.
- Phishing messages can be hidden using white font on a white background within emails.
- Gemini reproduces text within tags, displaying phishing content in summaries.
- The exploit was discovered and reported by researcher Marco Figueroa.
- Google has not yet confirmed if the vulnerability has been patched.
Already a member? Log in here