← heapsort-ai

Google Gemini

27 items

RESEARCHDEV.to AI·5d ago

Indirect Prompt Injection via Notifications Hijacks Google Gemini on Android

A SafeBreach researcher demonstrated an indirect prompt injection vulnerability in Google Gemini on Android, allowing the assistant to execute real device actions without user awareness via notifications. While Google has patched the issue, the research exposes a large attack surface where any app capable of pushing a notification becomes a potential injection vector.

28
ARTICLEDEV.to AI·5d ago

Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

Researchers uncovered a prompt injection vulnerability in Google Gemini on Android, where content from app notifications like WhatsApp and Slack could be misinterpreted as malicious instructions. This flaw allows an attacker to potentially control Gemini to open browsers, send messages, or poison its long-term memory, all without requiring a malicious app or special permissions.

28