Search

Critical Vulnerability Found in Gemini Feature of Gmail

15 July 2025

A critical vulnerability has been identified in the Gemini function integrated into Gmail, allowing hackers to execute phishing attacks through artificially generated email summaries. This was reported by BleepingComputer citing 0DIN.

The flaw was discovered by Marco Figueroa, manager of the GenAI Bug Bounty program at Mozilla. Figueroa notes that attackers can conceal instructions in the body of an email by formatting them in white and reducing the font size to zero, making the text invisible to the human eye but accessible for Gemini analysis. As a result, AI can automatically add misleading alerts to the summaries, such as fake password breach notifications, along with phony support numbers.

While some users may disregard such messages, others could fall victim due to the emotional manipulation involved. Figueroa emphasizes that security teams can develop methods to detect hidden information and analyze AI-generated summaries for the presence of URLs, phone numbers, or urgent messages.

BleepingComputer reached out to Google regarding this vulnerability in Gemini. A company representative stated that no evidence of exploitation has been seen so far, but added that Google is already working on protective measures and will introduce additional security protocols soon.