GeminiJack vulnerability exposed sensitive corporate data after researchers found a zero-click flaw in Google’s enterprise AI tools. The issue allowed attackers to trigger data leaks during routine searches without any user action.
Zero-click flaw enabled silent exploitation
The vulnerability affected Gemini Enterprise and its earlier link with Vertex AI Search. These systems help organizations search Gmail, Docs, Calendar, and other Workspace data. The flaw allowed attackers to plant hidden instructions inside normal files. When employees performed routine searches, the AI processed these instructions as valid commands.
The exploit required no clicks, downloads, or manual interaction. Any poisoned document inside a company’s Workspace environment could trigger the attack. This made the GeminiJack vulnerability particularly dangerous for large organizations with broad shared storage.
How attackers planted hidden commands
Researchers found that attackers could embed invisible prompt injections inside standard Workspace items. These items included Google Docs, Calendar invitations, and regular emails. The malicious content remained dormant until an employee used Gemini Enterprise to search internal data.
Once the AI retrieved the poisoned content, it executed the hidden instructions. Attackers then redirected the AI to exfiltrate data through disguised image requests. These outbound requests looked harmless and avoided detection by standard monitoring tools.
Data at risk across Workspace
The GeminiJack vulnerability allowed access to many types of confidential information. The exposed data included inbox records, private calendar events, shared documents, and sensitive business materials. Because the AI had broad retrieval permissions, a single poisoned file could reveal years of internal communication.
Traditional security tools did not detect these leaks. The AI acted as the transfer mechanism, and the traffic appeared normal to systems designed to catch malware or unauthorized access attempts.
Google’s mitigation and response
Google addressed the flaw after receiving a detailed report from researchers. The company deployed updates that changed how Gemini Enterprise interacts with stored Workspace data. It also separated key components that previously enabled the exploit path.
Google stated that the fix prevents malicious content from being executed as instructions. The company continues to refine its AI safety controls in response to emerging threats linked to prompt manipulation.
Broader risks for enterprise AI
The GeminiJack vulnerability highlights a new category of risks faced by organizations adopting AI-driven tools. Enterprise AI systems can blur the line between user content and system commands. When these boundaries break, attackers can exploit trusted tools to access internal data.
The incident also shows that attackers no longer need traditional malware to reach sensitive information. As AI becomes central to corporate workflows, organizations must strengthen validation, monitoring, and content controls around their AI platforms.
Conclusion
The GeminiJack vulnerability demonstrates how zero-click flaws in enterprise AI systems can expose critical corporate data. Hidden instructions inside normal files allowed attackers to misuse Google’s AI and extract information from Gmail, Docs, and Calendar. The event underscores the urgent need for improved safeguards that protect AI tools from manipulation and secure sensitive data across modern organizations.


0 responses to “GeminiJack Vulnerability Exposes Corporate Gmail, Docs, and Calendar Data”