Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securitycloud-service-vulnerabilitydata-exfiltration-method

GeminiJack No-Click Prompt Injection Vulnerability in Google Gemini Enterprise

Updated 3mo agoFirst seen Dec 9, 20257 sources

Google addressed a critical vulnerability in its Gemini Enterprise AI assistant, identified as GeminiJack, which allowed attackers to exfiltrate sensitive corporate data through a no-click prompt injection attack. Discovered by Noma Labs, the flaw enabled malicious actors to embed hidden instructions within commonly shared documents, calendar invites, or emails. When an employee performed a standard search using Gemini Enterprise, the AI could automatically retrieve and execute these hidden instructions, granting attackers access to confidential information without any user interaction or warning.

The vulnerability stemmed from an architectural weakness in how Gemini Enterprise and Vertex AI Search interpret and process information across integrated Workspace data sources, including Gmail, Calendar, and Docs. Attackers could leverage this flaw to extract entire document stores, calendar histories, and years of email records by simply embedding indirect prompt injections in shared artifacts. Google has since fixed the issue following responsible disclosure by Noma Security, highlighting the risks associated with integrating AI assistants into enterprise environments without robust safeguards against prompt injection attacks.

Share:
GeminiJack No-Click Prompt Injection Vulnerability in Google Gemini Enterprise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 9, 20257mo ago

Public disclosure of GeminiJack and Google's patch

Multiple security outlets reported that Google had fixed the GeminiJack zero-click flaw, which could silently exfiltrate sensitive corporate Google Workspace data without user interaction. Public reporting also detailed the indirect prompt-injection technique, affected products, and the difficulty of detecting the attack.

Google deploys architectural changes to mitigate GeminiJack

Google patched the vulnerability by changing how Gemini Enterprise and Vertex AI Search interact with indexed and retrieved data. As part of the mitigation, Vertex AI Search was separated from Gemini Enterprise and no longer shared the same RAG capabilities.

Jun 1, 20251y ago

Google and Noma validate the GeminiJack exploit

After disclosure, Google worked with Noma to validate that poisoned Workspace content such as documents, emails, or calendar invites could cause Gemini to retrieve sensitive data and exfiltrate it through attacker-controlled image requests. The research established the issue as an architectural weakness in Gemini's retrieval-augmented generation workflow.

May 6, 20251y ago

Noma Security reports GeminiJack to Google

Noma Security/Noma Labs discovered the GeminiJack zero-click prompt-injection flaw affecting Gemini Enterprise and Vertex AI Search and reported it to Google. Sources conflict on the exact report date, with references citing May 6, 2025, June 5, 2025, and August 2025 as the date Google received the report.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
7 linked
GmailGoogle DocsGmailGmailGoogle DocsGmailGmail
Organizations
7 linked
Noma SecurityGoogleSalesforceSectigoBugcrowdOasis SecurityHackread.com
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.