high

Hacking Google Bard via Prompt Injection

Published Fri, Nov 3rd, 2023
Platforms

Summary

A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

Affected Services

Google Bard

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Entry Status
Stub (AI-Generated)
Disclosure Date
Tue, Sep 19th, 2023
Exploitablity Period
Until 2023/10/19
Known ITW Exploitation
-
Detection Methods
Monitor for unexpected image rendering in Google Bard conversations and unusual data access patterns in Google Docs and Gmail linked to Bard.
Piercing Index Rating
-
Discovered by
wunderwuzzi, Embrace The Red