Smashing Security

Poisoned Calendar invites, ChatGPT, and Bromide

16 snips
Aug 13, 2025
Dave Bittner, a cybersecurity expert from The Cyberwire and host of Hacking Humans, joins the banter-filled discussion. They explore the alarming security risks of poisoned Google Calendar invites that could breach smart home devices. A wild story emerges about a man hospitalized after he took ChatGPT's bizarre seasoning advice. The conversation lightens up with thoughts on the new Superman movie and its focus on kindness, alongside humorous movie recommendations, making for a lively and engaging exchange.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Calendar Invites Can Deliver Commands

  • Researchers demonstrated that malicious text in Google Calendar invites can be interpreted as commands by Gemini and trigger other services.
  • That chained access can manipulate smart-home devices or exfiltrate emails without the user's intent.
INSIGHT

AI Summaries Can Act Like Injection Points

  • Gemini summarising calendar events may inadvertently execute embedded instructions if prompts aren’t sanitized.
  • The attack resembles injection exploits where benign inputs are turned into actionable commands by an agent.
ADVICE

Require Confirmation For Sensitive Actions

  • Google has added filters and confirmation prompts for sensitive actions triggered via Gemini.
  • Users should ensure their AI assistants require explicit confirmation before taking sensitive actions.
Get the Snipd Podcast app to discover more snips from this episode
Get the app