Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Gadgets»Gemini in Gmail is unsafe for injection-based fishing attacks, researcher finds
    Gadgets

    Gemini in Gmail is unsafe for injection-based fishing attacks, researcher finds

    PineapplesUpdateBy PineapplesUpdateJuly 15, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Gemini in Gmail is unsafe for injection-based fishing attacks, researcher finds
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Gemini injection in Gmail is unsafe to accelerate injection-based fishing attacks, a researcher performed. According to the researcher, Artificial Intelligence (AI) Chatbott that offers features such as email summary generation and email rewriting can be manipulated to display users. This vulnerability pursues a significant risk, as the attackers can potentially take advantage of it to operate online scams. Meanwhile, the Mountain view-based tech veteran allegedly stated that it has not yet seen this manipulation technique used against users.

    The researcher claims that Gemini is insecure to accelerate injections in Gmail

    Was vulnerable Spibled and performed By researcher Marco Figuero, Jenai Bug Bounty Program Manager at Mozilla, AI Tools through Bag Bunty Program of Mozilla, through 0 dein. Interestingly, to trigger this vulnerability, the scammer does not need to pull any high-profile cyber heirs. Instead, it can be done with a simple text command, which is known as early injections.

    Prompt injection is a type of attack on AI chatbots where an attacker deliberately manipulates input or promises to behave the model in an unexpected or malicious manner. In this particular scenario, the researcher used indirect early injections, where malicious signs are embedded inside a document, email or a web page.

    According to the researcher, he just wrote a long email and finally added some hidden text, including early injections. There was no URL or Attachment in the email, making it easier to reach the receiver’s primary inbox.

    Gemini in Gmail is unsafe for injection-based fishing attacks, researcher finds

    Adding a hidden malicious message to the email
    Photo Credit: 0DIN/Marco Figueroa

    As shown in the image, the attacker used a white color font on a white page to write malicious messages. This lesson is generally invisible to the receiver of email. Other methods of connecting hidden text include using a zero font size, off-screen text placement and other HTML or CSS tricks.

    Now, if the receiver uses Gemini’s “email” facility, the chatbot will process the hidden text and take the command, without finding the user ever detecting, Figuro said. He also said that the chances of chatbot increase after the command if the message is wrapped inside a administrator tag, as it considers high-primary request.

    Gemini hack 2 0din Gemini in Gmail vulnerability

    Gemini repeats malicious messages in Verbatim Summary
    Photo Credit: 0DIN/Marco Figueroa

    The cyber security researcher showed in another screenshot that Mithun gave a really malicious message and displayed it as part of his email summary. Since the message is now coming from Gemini, rather than an email from a potential stranger, the victim may be more likely to believe and follow instructions, falling for the scam.

    BlappingCopper Contacted For Google to ask about vulnerability, and a spokesperson said the company has not seen any evidence of similar manipulation so far. Additionally, it was also revealed that Google is in the process of implementing some mitigations to quick injection-based adverse attacks.

    attacks finds Fishing Gemini Gmail injectionbased researcher unsafe
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAndroid Malware uses distorted APK to detect konfety
    Next Article Develop a garden pet mutation tier list – Best mutation for pets – gamezebo
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    I’ve tested Gemini, ChatGPT, Copilot, and others – Lenovo has all the AI ​​assistants to beat

    January 10, 2026
    Startups

    Your Gmail is getting an AI makeover – here’s what to expect and when

    January 8, 2026
    Startups

    I got an early demo of AI smart glasses with Gemini, and they’re almost too ambitious

    December 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    This browser is designed for those who never close tabs

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.