Hot topics

This ‘Simple’ Command Could Wreak Havoc in Your Home

Google Home hijack via Gemini AI chatbot
© nextpit

Read in other languages:

One of Gemini's advantages is its support for natural language, enabling users to provide commands similar to chatting with a person rather than using complex codes or jargon. However, this ability could also present a flaw that allows attackers to trick Google's AI into wreaking havoc in your home by executing nefarious actions, even without direct access.

AI Can Be Used to Hijack Your Home

A cybersecurity research team has demonstrated how Google's digital assistant can be easily tricked using simple prompts or an indirect prompt injection attack. This is also dubbed as "promptware," as reported by Wired. Attackers can use this method to insert malicious code and commands into the chatbot, and then manipulate smart home devices even without being given direct access or privilege.

The team was able to fool Gemini by using promptware attacks through Google Calendar invites. Specifically, they described that a user would just need to open Gemini, then ask for a summary of their calendar, and simply follow up with a response of "thank you." This would be enough to carry out actions that the owner never explicitly authorized.

In the example, once the commands were issued, Gemini demonstrated the ability to turn off lights, close window curtains, and even activate a smart boiler. While these actions may seem minor, they pose a serious risk to users, especially if triggered unintentionally or maliciously.

Google Has Fixed the Vulnerability

The good news is that this loophole was not reported to have been exploited by bad actors in the wild. And before the attack was presented at the ongoing Black Hat conference, the team had already brought it to Google's attention back in February. The company said that they have patched the issue since then.

It added that while attacks like these are very rare and require extensive preparation, the nature of these vulnerabilities is very hard to defend against.

This is not the first time that a similar case of how actors can manipulate an AI model has been reported. Back in June, it was reported that nation-state hackers from Russia, China, and Iran have used OpenAI's ChatGPT to develop malware that would be used for scams and social media disinformation. OpenAI was believed to have taken down accounts linked to these activities.

These cases present glaring lapses in the use of artificial intelligence, despite how companies are heavily investing in the development of the technologies behind these chatbots. The question is, do you think it's safe to trust these chatbots with your personal data and devices? We'd like to hear your opinion in the comments.

Source: Wired

 The best gaming monitors at a glance

  Best gaming monitor up to $400 Best gaming monitor up to $600 Best gaming monitor up to $800 Best gaming monitor up to $1,000 Best gaming monitor for consoles
Model
Image LG Ultragear 27GP850P - product image Asus ROG Strix XG27AQ - product image BenQ MOBIUZ EX3210U - product image Asus ROG Swift PG27AQDM - product image Gigabyte M32U - product image
Offers
nextpit receives a commission for purchases made via the marked links. This has no influence on the editorial content and there are no costs for you. You can find out more about how we make money on our transparency page.
Go to comment (0)
Jade Bryan

Jade Bryan
Junior Editor

I still remember how amazed I was when I first got hold of the Nokia 3210 back when I was a kid, and it was during that time I developed my love for technology, particularly for mobile phones. I started sharing my knowledge through writing in different blogs and forums back in Nokia Nseries era. I even make videos before where I put different phones side-by-side. Today, I'm still an avid enthusiast of smartphones, but my interests have evolved into smart devices and electric vehicles.

To the author profile
Liked this article? Share now!
Recommended articles
Latest articles
Push notification Next article
No comments
Write new comment:
All changes will be saved. No drafts are saved when editing
Write new comment:
All changes will be saved. No drafts are saved when editing