Hacker News
Read post

From Prompt Injection to Data Exfiltration · Embrace The Red

Google Bard recently received powerful updates, including Extensions that allow it to access YouTube, search for flights and hotels, and access a user's personal documents and emails. This opens up the possibility for Indirect Prompt Injection attacks via emails or Google Docs. The article explains the vulnerability of Bard to image markdown injection and the bypass of Google's Content Security Policy. It also showcases a demo and the timeline of the fix for the issue.

    #data-exfiltration#google-bard#prompt-injection#security
Nov 13, 2023•5m read time•From embracethered.com
Post cover image
Table of contents
What’s next?The Vulnerability - Image Markdown InjectionContent Security Policy BypassWriting the Bard LoggerDemo and Responsible DisclosureShow me the Shell CodeScreenshotsGoogle’s FixConclusionFix TimelineReferencesAppendix
32 Impressions
Hacker News's image
Hacker News

Hacker News is a community-driven platform for sharing and discussing technology news, startups, and...

17.4K Followers

•

141.8K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard