Close Menu
Global News HQ
    What's Hot

    Curbed’s 20 Most-Read Stories of 2025

    December 17, 2025

    Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)

    December 17, 2025

    Crypto Investment Products See Third Week of Gains Led by US Investors

    December 17, 2025
    Recent Posts
    • Curbed’s 20 Most-Read Stories of 2025
    • Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)
    • Crypto Investment Products See Third Week of Gains Led by US Investors
    • JetBlue cuts JFK-Amsterdam route; Boston flights to continue – The Points Guy
    • Max Mara Pre-Fall 2026 Collection
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Curbed’s 20 Most-Read Stories of 2025
    • Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)
    • Crypto Investment Products See Third Week of Gains Led by US Investors
    • JetBlue cuts JFK-Amsterdam route; Boston flights to continue – The Points Guy
    • Max Mara Pre-Fall 2026 Collection
    • Former DLA Piper Associate Accuses ‘High-Ranking Firm Partner’ of Assault in Firm’s Dela. Office| Law.com
    • DIY Bows Are the Best (and Easiest!) Last-Minute Christmas Decor
    • Does Mortgage Pre-Approval Affect Your Credit Score? What Homebuyers Should Know
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Technology & Gadgets - Compromised Google Calendar invites can hijack ChatGPT’s Gmail connector and leak emails
    Technology & Gadgets

    Compromised Google Calendar invites can hijack ChatGPT’s Gmail connector and leak emails

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Compromised Google Calendar invites can hijack ChatGPT’s Gmail connector and leak emails
    Share
    Facebook Twitter LinkedIn Pinterest Email



    A security researcher has demonstrated how a malicious Google Calendar invite can prompt-inject ChatGPT and coax it into leaking private emails once Google connectors are enabled. In a post onX, on September 12, Eito Miyamura outlines a simple scenario: An attacker sends a calendar invitation seeded with instructions and waits for the target to engage with ChatGPT and ask it to perform an action. ChatGPT then reads the booby-trapped event and follows orders to search Gmail and follow sensitive details. “All you need? The victim’s email address,” Miyamura claims.

    In mid-August, OpenAI introduced native Gmail, Google Calendar, and Google Contacts connectors in ChatGPT, initially to Pro users and subsequently to Plus, with release notes stating that the assistant can automatically reference these sources in chat after authorization. That means a casual, “What’s on my calendar today?” can pull data directly from your Google account without you explicitly choosing a source each time.

    OpenAI’s help center goes further, spelling out that automatic use is enabled for these Google connectors once enabled, and that you can turn it off in ChatGPT’s settings if you prefer to select sources manually. The same page explains that custom connectors using the Model Context Protocol are intended for developers and are not identified by OpenAI. This is particularly important to note because Miyamura frames the attack in the context of recent MCP support and rapidly growing tool ecosystems.


    You may like

    We got ChatGPT to leak your private email data 💀💀All you need? The victim’s email address. ⛓️‍💥🚩📧On Wednesday, @OpenAI added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion,… pic.twitter.com/E5VuhZp2u2September 12, 2025

    What’s happening under the hood is indirect prompt injection. The attacker’s instructions are hidden inside data that the assistant is allowed to read — in this case, the text of a calendar event. In August, researchers demonstrated how a compromised invite could steer Google’s Gemini into controlling smart-home devices and leaking information, work that has since been documented in both security write-ups and a paper titled “Invitation Is All You Need.” The technicalities differ by platform, but the core risk is the same once an assistant is permitted to read compromised calendar content.

    Ultimately, nothing happens unless you first connect Gmail and Calendar inside ChatGPT, and the assistant’s behavior still depends on the policies and prompts OpenAI applies when it ingests third-party content. Documentation also notes that you can disconnect sources or disable automatic use, which limits opportunities for a compromised event to influence a routine chat.

    If you’re concerned, the most effective fix is on the Google side. Change Google Calendar’s “Automatically add invitations” setting so only invitations from known senders or those you accept appear on your calendar, and consider hiding declined events. Google’s support pages walk through those options in detail, and Google Workspace administrators can set safer defaults organization-wide.

    The broader takeaway from this isn’t that ChatGPT or Gmail has been “hacked,” but that tool-using AI is unusually susceptible to hostile instructions lurking in the data you let it read. The connectors that make these assistants somewhat useful also expand the attack surface to calendars and inboxes. Until the industry ships stronger, default-on defenses against indirect prompt injection, the safest course of action is to be conservative about which accounts you connect and, in this specific scenario, lock down your calendar so strangers cannot plant surprises.

    Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.

    Follow Tom’s Hardware on Google News, or add us as a preferred source, to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleSouthwest Airlines adds Sonoma County in California expansion – The Points Guy
    Next Article I’m a Cleaning Editor, And I Just Realized I’ve Been Making a Huge Laundry Mistake for Years

    Related Posts

    Arctic launches its best thermal paste yet for chips of all types — claims new MX-7 formulation runs 3% cooler than its predecessor

    December 16, 2025

    Utah leaders hinder efforts to develop solar energy supply

    December 16, 2025

    The AirPods Pro 3 are $40 off right now on Amazon

    December 16, 2025

    Today's NYT Connections: Sports Edition Hints, Answers for Dec. 16 #449

    December 16, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Real Estate
    6 Mins Read

    Curbed’s 20 Most-Read Stories of 2025

    Photo-Illustration: Curbed; Photos: Lacy Land, Stevie Remsberg, Millie von Platen, Stephen Kent Johnson At the…

    Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)

    December 17, 2025

    Crypto Investment Products See Third Week of Gains Led by US Investors

    December 17, 2025

    JetBlue cuts JFK-Amsterdam route; Boston flights to continue – The Points Guy

    December 17, 2025
    Top
    Real Estate
    6 Mins Read

    Curbed’s 20 Most-Read Stories of 2025

    Photo-Illustration: Curbed; Photos: Lacy Land, Stevie Remsberg, Millie von Platen, Stephen Kent Johnson At the…

    Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)

    December 17, 2025

    Crypto Investment Products See Third Week of Gains Led by US Investors

    December 17, 2025
    Our Picks
    Real Estate
    6 Mins Read

    Curbed’s 20 Most-Read Stories of 2025

    Photo-Illustration: Curbed; Photos: Lacy Land, Stevie Remsberg, Millie von Platen, Stephen Kent Johnson At the…

    Finance & Investment
    3 Mins Read

    Alector Stock Down After Latozinemab Failure, Eyes On Phase 2 Catalyst (ALEC)

    This article was written byFollowI hold a Master’s degree in Cell Biology and began my…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version