A researcher found a multi-layer sanitization gap in Google Gemini. It let attackers pull off indirect prompt injections to leak Workspace data - think Gmail, Drive, Calendar - using Markdown image renders across Gemini and Colab export chains.
The trick? Sneaking through cracks between HTML and Markdown parsing, plus some wild URI linkification edge cases that Geminiβs Markdown sanitizer missed.









