They are encoding commands in calendar events there is not a vulnerability in Google calendar. After your device is compromised its commanded to subscribe to a calendar. Those events have commands. Since checking your calendar is a normal event unlike connecting to a nefarious server it becomes more difficult to discover.
It’s even worse than that. You can buy seeds from the market place have no agreement with Monsanto but can’t plant those seeds.
https://en.m.wikipedia.org/wiki/Bowman_v._Monsanto_Co.