|
|
|
|
|
by doakes
840 days ago
|
|
So is the idea (for the last/$20k one) that you would convince someone to paste your maliciously crafted prompt to steal their data? The other post[0] of the same exploit is really interesting b/c it reads instructions from a document. So if someone had something like "find X in my documents" and you shared the malicious document with them, it could trigger those instructions. [0] https://embracethered.com/blog/posts/2023/google-bard-data-e... |
|
If a unknowing user asks a simple question, and Gemini reaches out to a malicious website for an answer, the prompt could be injected.
Additionally it could be taken out of an email / doc that was previously sent to the innocent user if the user asked Gemini to search their email or docs or something.
Kind of crazy the number of delivery vectors there are for these connected LLMs