The other post[0] of the same exploit is really interesting b/c it reads instructions from a document. So if someone had something like "find X in my documents" and you shared the malicious document with them, it could trigger those instructions.
[0] https://embracethered.com/blog/posts/2023/google-bard-data-e...