Smart home AI risks escalate as calendar invites threaten device security

A demonstration of Gemini-powered smart home devices being hijacked through malicious calendar entries highlights growing vulnerabilities in AI-connected systems, urging tighter control measures to prevent potentially dangerous manipulations.

A Gemini-powered smart home setup has shown how a routine calendar entry can be misread as an instruction to buy something, with a dentist appointment apparently triggering an order for cupcakes. The episode, described in a post by Forkast, was not a lab exercise or a deliberate red-team test, but a normal scheduling entry that the assistant treated as an actionable commerce request. It is a small mistake with an important implication: the same mechanism that can order snacks can also be pointed at more sensitive actions if the surrounding systems are not tightly controlled.

Security researchers have been warning for some time that this is a structural weakness in AI agents that ingest external content. According to reports from TechRadar, Android Authority and Tom’s Guide, Tel Aviv University researchers showed that a poisoned Google Calendar invite could be used to hijack Gemini-powered smart home devices through indirect prompt injection. In those demonstrations, malicious instructions hidden inside calendar text were later executed when the assistant summarised the user’s schedule, leading to actions such as switching lights, opening windows, turning off a boiler, starting Zoom calls and, in some cases, exposing data held elsewhere in the connected environment.

The broader concern is not limited to one product. The same pattern has been seen in other consumer AI and connected-device systems, including Meta’s Muse agent exposing private iCloud photos during testing and DJI Romo token leaks that revealed how fragile backend design can expose sensitive device data. Together, these examples point to a common failure mode: consumer platforms are increasingly connecting assistants to calendars, email, cameras, locks and shopping tools, but without the runtime controls that enterprise agent security products are beginning to provide.

That distinction matters because an assistant cannot reliably tell whether text is merely content or a command unless the system enforces that boundary. In the calendar case, the danger was not that Gemini was “hacked” in the traditional sense, but that it interpreted untrusted text as something it should act on. Once an AI can move from reading a calendar invite to triggering a purchase or a device command, the gap between convenience and risk becomes very small.

Google has said the specific flaws demonstrated by researchers have been fixed, but experts quoted in the coverage cautioned that similar attacks remain a live issue wherever external text feeds directly into tool use. For homeowners, the practical lesson is straightforward: any assistant with the power to spend money, unlock devices or control appliances should be treated as a security boundary, not just a convenience feature. If there is no scanning, policy layer or audit trail between the incoming content and the tool call, the system is relying on guesswork to distinguish an appointment from an order.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.