Calendar Invites Can Hijack Smart Homes Through Google's Gemini AI
Researchers from Tel Aviv University and security firm SafeBreach have discovered a vulnerability in Google's Gemini AI that allows hackers to control smart home devices through calendar invites.
The team demonstrated how embedding malicious instructions into Google Calendar invite titles can hijack Gemini, leading to physical-world consequences such as toggling lights, operating shutters, and activating boilers.
The mechanism relies on a technique called delayed automatic tool invocation, where the AI reads the invite, absorbs the hidden commands, and waits for a user request to execute the attack.
According to the researchers' TARA risk assessment, 73% of the threats they analyzed were rated high-to-critical risk for end users. This vulnerability has significant implications for smart home owners and companies building agent platforms.