back_icon
Back
/ARTICLES/

Now Available: Prevent Prompt Injection and Gemini Jailbreak Attacks in Gmail with MagicMirror

blog_imageblog_image
Prompt injection vulnerabilities in Gemini’s Gmail summarizer expose users to hidden threats. MagicMirror gives teams control where Google does not.
News
Jul 27, 2025

MagicMirror now gives customers protection over the recent prompt injection vulnerabilities found in Gemini’s summarization feature inside Gmail. These vulnerabilities expose users unknowingly to hidden threats.

The Risk: Prompt Injection in Gemini’s Email Summarization

Gemini’s summarization tool inside Gmail can be exploited. Recent research, including coverage by SecurityWeek, confirms that attackers are embedding hidden prompts inside emails. When a user clicks “Summarize this email,” Gemini executes those invisible instructions, potentially injecting phishing content, rewriting tone or intent, or displaying manipulated summaries.

This behavior is not visible to the user and is not currently controllable by admins through Google Workspace.

Gemini summarization runs inside Gmail’s interface, making it difficult for IT or security teams to observe or manage. These prompt-injection attacks bypass traditional email filters and endpoint monitoring tools. Attackers know this. Search traffic for terms like “Gemini email jailbreak” has surged. Across Reddit and jailbreak forums, users are actively experimenting with ways to manipulate Gemini’s outputs.

Google currently does not provide a way to disable this feature. For many organizations, that leaves a visible risk with no available response.

MagicMirror’s Response: Real-Time, Browser-Level Enforcement

MagicMirror now enables organizations to block Gemini’s Gmail summarization feature directly within their GenAI policy settings.

This update reflects MagicMirror’s mission to give teams real-time observability and protection at the point of GenAI interaction, without disrupting core workflows or introducing external data exposure.

When enabled:

  • The summarization feature is disabled inside Gmail
  • Gmail’s writing assistant (used during email composition) remains available as it does not pose the same threat.
  • The policy propagates across users within 5 minutes

No additional configuration or software update is required. All enforcement happens locally, through the MagicMirror browser extension.

Why Visibility into GenAI Usage Matters

This is exactly the kind of GenAI behavior that organizations need to observe and control. It operates within a trusted UI. It creates outputs that users don't expect. And it exposes companies to risks that can’t be seen in traditional traffic logs or device monitors.

MagicMirror provides:

  • Real-time insight into GenAI tool usage
  • Prompt-level observability and risk classification
  • Local enforcement with no cloud exposure

Designed for GenAI-First Teams

MagicMirror is a GenAI observability and protection platform, not a traditional security tool. It provides organizations with visibility into how GenAI tools, such as Gemini, ChatGPT, and Copilot, are being utilized and offers browser-level safeguards to manage usage responsibly.

This feature supports a key use case for teams developing GenAI policies: understanding what tools are in use, how they're being used, and where to apply targeted controls without slowing teams down.

The feature is opt-in by design, reflecting our commitment to flexible, user-aligned governance.

articles-dtl-icon
Link copied to clipboard!

Fast, Private, and Flexible Security

We are currently onboarding a few design partners. If you are looking for NextGen security solution that is private, flexible and non-disrubtive we want to talk to you.
Invalid email address. Please add a valid workspace email.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.