Calendar Invites Now Pose Risks to Smart Home Devices

Researchers have shown that simple calendar entries can trick AI assistants into controlling physical home systems without user intent.
Your digital calendar is likely the most overlooked security risk in your smart home. Researchers from Tel Aviv University, the Technion, and security firm SafeBreach have demonstrated that malicious instructions hidden within calendar invite titles can hijack AI assistants like Google’s Gemini. This is not a theoretical glitch; it is a documented method for taking control of physical devices.
The study, titled 'Invitation Is All You Need,' reveals that 14 different prompt injection attacks can be executed through web, mobile, and voice platforms. The most alarming aspect is that these digital manipulations result in real-world physical actions, such as toggling lights, opening shutters, and activating boilers. This marks the first confirmed instance of a prompt injection attack causing direct physical consequences in a connected home.
Hidden commands trigger physical actions
The attack mechanism relies on a technique called delayed automatic tool invocation. An attacker sends a calendar invite with hidden commands buried in the title. When the victim asks the AI to summarize their schedule, the system reads the invite and absorbs the malicious instructions. It then waits for a reflexive user response, such as saying 'thanks,' to execute the commands. The AI believes it is following a legitimate request, but it is actually performing an unauthorized action.
According to a risk assessment by the researchers, 73% of the analyzed threats are rated as high to critical for end users. In their demonstrations, the AI was shown turning lights on and off, moving smart shutters, and heating a boiler. These are not just digital notifications; they are physical changes that affect the safety and comfort of the home. The stakes are high because these actions occur without the user’s explicit consent for that specific command.
Google implements new defensive layers
Google has responded by accelerating the deployment of new security measures. According to Andy Wen, Senior Director of Security Product Management for Workspace, the research directly influenced these updates. The company now uses machine learning classifiers to detect malicious prompts at input, reasoning, and output stages. They have also introduced security thought reinforcement, which steers the AI to ignore adversarial instructions, and a user confirmation framework that requires explicit permission before sensitive actions are taken.
However, a dispute remains between Google and the researchers. Google argues that such attacks are exceedingly rare and that the researchers had to change default calendar settings to enable the exploits. The researchers counter that variants of the attack work via email subject lines and document titles, channels that require no settings changes. This suggests that while the calendar is a dramatic vector, it is not the only entry point for such vulnerabilities.
Security lags behind rapid expansion
This vulnerability highlights a broader pattern in the consumer AI industry: platforms are expanding faster than their security layers. As companies like Sonos launch open platforms for millions of devices, the economics often favor open access over bundled security. Recent breaches, such as the DJI Romo incident that exposed thousands of robot vacuums, show that a single leaked token can compromise global systems. The current regulatory framework is not designed for this specific threat model.
As AI agents become more integrated into physical environments, the risk of unauthorized control grows. Users should be aware that their scheduling tools are now part of the attack surface. While defenses are improving, the trade-off between convenience and security remains a significant concern. The ability of a simple text field to command physical hardware represents a fundamental shift in how we need to think about digital trust.






