Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Gemini Vulnerability Exploited via Messaging Apps

Google Gemini Vulnerability Exploited via Messaging Apps

Posted on June 3, 2026 By CWS

A recent wave of indirect prompt injection attacks has exposed vulnerabilities in Google Gemini’s voice assistant. These exploits enable attackers to covertly commandeer the AI using harmful payloads sent through widely-used messaging platforms like WhatsApp, Slack, and SMS.

Understanding the New Exploit

Research led by Or Yair from SafeBreach outlines how this new security flaw expands upon previous findings. Earlier, Google Calendar invitations were weaponized, but the current attack method uses any app capable of sending device notifications as a potential delivery channel.

The exploit primarily targets the Android Utilities agent within Gemini, which processes incoming notifications. By embedding harmful instructions within these messages, attackers can manipulate Gemini’s responses without the user’s awareness. This context poisoning allows for phishing attempts, such as delivering deceptive system messages.

Bypassing Google’s Security Measures

Efforts by Google to patch previous vulnerabilities included blocking tool invocation methods, but SafeBreach introduced a new bypass technique called Fake Context Alignment. This approach tricks Gemini’s security mechanisms by presenting a false sense of authorization.

Two variations of this technique were demonstrated. The first, Obfuscated Fake Context Alignment, combines a concealed malicious question in a foreign language with a benign English prompt. The second, Muted Fake Context Alignment, uses hidden clickable text, which Gemini’s text-to-speech feature skips, misleading the user into authorizing tool execution unknowingly.

Implications for Smart Home Devices

These vulnerabilities have serious implications for smart homes. Attackers can control connected devices such as lighting and windows via Google Home. The techniques also allow for covert video streaming by remotely activating video conferencing software, posing significant privacy threats.

Additionally, large-scale social engineering attacks are increasingly prevalent. Messages appear to originate from trusted contacts by extracting real names from notification queues. Persistent memory poisoning further complicates matters, embedding false data across the user’s Google Workspace devices.

Google’s Response and Mitigation Efforts

SafeBreach reported these findings to Google’s Vulnerability Reward Program on August 17, 2025. By November 14, 2025, Google confirmed the deployment of content classifier updates that effectively countered the described attack methods.

This discovery underscores the importance of robust cybersecurity measures, particularly as smart technology becomes more integrated into daily life. Users are encouraged to stay informed about potential risks and participate in awareness programs like the upcoming webinar on OWASP API Top 10 and WAAP guidance.

Cyber Security News Tags:Android Utilities, context poisoning, Cybersecurity, fake context alignment, Google Gemini, Messaging Apps, prompt injection, SafeBreach, smart home exploitation, Vulnerability

Post navigation

Previous Post: Google Gemini Vulnerability Exposed by Notifications
Next Post: New Malspam Campaign Exploits Google DoubleClick

Related Posts

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data Cyber Security News
New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer Cyber Security News
KimJongRAT Attacking Windows Users via Weaponized .hta Files to Steal Logins KimJongRAT Attacking Windows Users via Weaponized .hta Files to Steal Logins Cyber Security News
Weaponized PyPI Package Steals Solana Private Keys Via Supply Chain Attack Weaponized PyPI Package Steals Solana Private Keys Via Supply Chain Attack Cyber Security News
DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks Cyber Security News
LangChainGo Vulnerability Let Attackers Access Sensitive Files LangChainGo Vulnerability Let Attackers Access Sensitive Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Malspam Campaign Exploits Google DoubleClick
  • Google Gemini Vulnerability Exploited via Messaging Apps
  • Google Gemini Vulnerability Exposed by Notifications
  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Malspam Campaign Exploits Google DoubleClick
  • Google Gemini Vulnerability Exploited via Messaging Apps
  • Google Gemini Vulnerability Exposed by Notifications
  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark