----------------
🎯 AI
===================
SafeBreach researcher Or Yair published findings demonstrating how poisoned notifications from messaging apps could hijack Google Gemini's voice assistant on Android through indirect prompt injection. The attack exploits Gemini's Utilities feature, which reads and replies to notifications from apps like WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. The agent that processes these notifications treats their text as instructions it can act on, creating what Yair called an "effectively infinite" attack surface. No malicious app needs to be installed on the target device.
Technical Details
The vulnerability is Android-specific. Gemini's Utilities feature does not exist on iOS or the web, which naturally limits the scope. The attack requires only that a hostile notification reaches the device through any app capable of pushing one.
At minimum, an attacker can rewrite what Gemini says, which includes forging a message from a named contact. In a hands-free scenario, such as driving, the user has no visual reference to verify whether a spoken message like "your manager asked you to upload the docs to this Drive folder" is legitimate.
The blind variant is more concerning. The payload fires after Gemini has loaded real notifications, grabs the first real sender name in the queue, and attributes the forged message to that person. This makes social engineering attacks significantly more convincing because the message appears to come from a known contact.
Beyond output manipulation, the attack can trigger real actions on the device. These include opening browser windows, launching a Zoom call, or poisoning Gemini's long-term memory so that false information persists across sessions. Memory poisoning is particularly noteworthy because it means the attack's effects outlast the initial notification.
Defense Bypass Context
This research follows SafeBreach's earlier "Invitation Is All You Need" work, which exploited malicious Google Calendar invites for similar prompt injection attacks. After that disclosure, Google hardened Gemini against indirect prompt injection. The added mitigation checked both the user's reply and Gemini's last output when deciding whether a "Yes" authorizes a sensitive action. Injecting a delayed instruction out of context caused Gemini to refuse, every time. Yair found a way around this mechanism through black-box testing.
Current Status
Google has since patched the vulnerability. SafeBreach lists no CVE for the issue, and there is no evidence the technique was ever used in the wild.
Detection Considerations
Organizations with Android devices running Gemini should ensure the latest patches are applied. The broader structural concern is that AI assistants processing untrusted input as context create trust boundaries that traditional application security models were not designed to address. Any notification-generating app on the device becomes a potential delivery vector for prompt injection when it feeds into an agent that acts on that content.
Limitations
Findings are based on black-box testing rather than source code review. The absence of a CVE and lack of observed wild exploitation mean the practical risk at time of disclosure was theoretical. The Android-only scope further limits the affected population.
🔹 PromptInjection #Gemini #AISecurity #Android #SafeBreach
🔗 Source: https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html?m=1