---
title: "From Prompt Injection to Data Exfiltration · Embrace The Red"
url: https://daily.dev/posts/from-prompt-injection-to-data-exfiltration-embrace-the-red-8zm3iqerb
source_url: https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/
type: article
source: "Hacker News"
published: 2023-11-13T19:24:51.564Z
updated: 2025-07-28T02:15:14.393Z
tags: ["data-exfiltration", "google-bard", "prompt-injection", "security"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# From Prompt Injection to Data Exfiltration · Embrace The Red

**[Hacker News](https://daily.dev/sources/hn)** · 5 min read · 0 upvotes · 0 comments

## Summary

Google Bard recently received powerful updates, including Extensions that allow it to access YouTube, search for flights and hotels, and access a user's personal documents and emails. This opens up the possibility for Indirect Prompt Injection attacks via emails or Google Docs. The article explains the vulnerability of Bard to image markdown injection and the bypass of Google's Content Security Policy. It also showcases a demo and the timeline of the fix for the issue.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#data-exfiltration](https://daily.dev/tags/data-exfiltration), [#google-bard](https://daily.dev/tags/google-bard), [#prompt-injection](https://daily.dev/tags/prompt-injection), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/from-prompt-injection-to-data-exfiltration-embrace-the-red-8zm3iqerb)
