Researchers reveal dangerous potential of calendar invites in hacking smart homes with AI

New research highlights how malicious calendar invites can exploit Google’s Gemini assistant, turning everyday scheduling tools into gateways for hacking connected home devices, a wake-up call for AI security in consumer tech.

A digital calendar is usually treated as routine infrastructure: a place for meetings, appointments and reminders. But researchers from Tel Aviv University, Technion and the security firm SafeBreach say it can also become a route into an AI-controlled home. Their work shows how a seemingly harmless calendar invite can be turned into a command channel for Google’s Gemini assistant, creating a new class of risk for connected devices. According to reporting by Reuters-style technology coverage and the research summaries, the problem is not limited to scheduling software; it sits at the junction of email, calendar services and home automation.

The study, published in August 2025 under the title “Invitation Is All You Need”, set out how malicious instructions hidden in Google Calendar invite titles could manipulate Gemini across web, mobile and Google Assistant interfaces. The researchers described 14 indirect prompt injection attacks and said their demonstrations produced physical outcomes, including switching lights, opening and closing smart shutters and triggering a boiler. Ars Technica and TechRadar reported that the team regarded this as the first documented prompt injection attack to have direct real-world effects.

The attack relies on what the researchers call delayed automatic tool invocation. In practice, an attacker places instructions inside an invite, Gemini later reads them when summarising a user’s diary, and the assistant then waits until a normal-seeming reply, such as “thanks”, to act on the hidden command. The researchers used the term “promptware” to describe this behaviour, highlighting that the weakness lies not just in the model’s language understanding, but in the way it can be induced to act on untrusted text from integrated services. Notebookcheck and TechNadu both described the technique as an exploitation of Gemini’s deep integration with Google’s own ecosystem.

The security implications are significant. The researchers said their TARA assessment rated 73% of the threats they examined as high to critical. They argued that calendar invites are only one route in; similar variants can travel through email subject lines and Google Docs titles, which weakens Google’s claim that the issue depends on unusual settings changes. Wired reported that Google responded with a broader set of mitigations, including machine learning-based content filters, stronger instruction-following controls, markdown sanitisation, suspicious URL redaction, user confirmation prompts for sensitive actions and security alerts for end users. Google later said these steps addressed the specific attacks.

The dispute also points to a wider problem in consumer AI and smart-home design. Security is lagging behind deployment, while the commercial pressure is to connect more services and expose them to more agents. As the reporting around the research notes, that is already visible in the growth of open platforms, subscription assistants and increasingly connected household devices. For users, the lesson is simple: any shared workspace that an AI can read may also become a path into the home. The smart home is no longer vulnerable only through its devices; it can be reached through the ordinary tools people use every day.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.