SECURITYDARK READING
Malicious Notifications Could Trick Google Gemini Users
A prompt injection flaw in Google Gemini's voice assistant allowed attackers to hide malicious commands in notifications, enabling social engineering and other attacks. The vulnerability could trick users through deceptive notifications, exploiting the assistant's processing of input.
Related Signal
Adjacent reporting
- Google Fixes AI Coding Tool Flaw That Let Attackers Execute Malicious Code: Report
- What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots
- Grafana Patches AI Bug That Could Have Leaked User Data
- Drupal: Critical SQL injection flaw now targeted in attacks
- Just like phishing for gullible humans, prompt injecting AIs is here to stay
- Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution