Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Gemini Vulnerability Exploited via Messaging Apps

Google Gemini Vulnerability Exploited via Messaging Apps

Posted on June 3, 2026 By CWS

A recent wave of indirect prompt injection attacks has exposed vulnerabilities in Google Gemini’s voice assistant. These exploits enable attackers to covertly commandeer the AI using harmful payloads sent through widely-used messaging platforms like WhatsApp, Slack, and SMS.

Understanding the New Exploit

Research led by Or Yair from SafeBreach outlines how this new security flaw expands upon previous findings. Earlier, Google Calendar invitations were weaponized, but the current attack method uses any app capable of sending device notifications as a potential delivery channel.

The exploit primarily targets the Android Utilities agent within Gemini, which processes incoming notifications. By embedding harmful instructions within these messages, attackers can manipulate Gemini’s responses without the user’s awareness. This context poisoning allows for phishing attempts, such as delivering deceptive system messages.

Bypassing Google’s Security Measures

Efforts by Google to patch previous vulnerabilities included blocking tool invocation methods, but SafeBreach introduced a new bypass technique called Fake Context Alignment. This approach tricks Gemini’s security mechanisms by presenting a false sense of authorization.

Two variations of this technique were demonstrated. The first, Obfuscated Fake Context Alignment, combines a concealed malicious question in a foreign language with a benign English prompt. The second, Muted Fake Context Alignment, uses hidden clickable text, which Gemini’s text-to-speech feature skips, misleading the user into authorizing tool execution unknowingly.

Implications for Smart Home Devices

These vulnerabilities have serious implications for smart homes. Attackers can control connected devices such as lighting and windows via Google Home. The techniques also allow for covert video streaming by remotely activating video conferencing software, posing significant privacy threats.

Additionally, large-scale social engineering attacks are increasingly prevalent. Messages appear to originate from trusted contacts by extracting real names from notification queues. Persistent memory poisoning further complicates matters, embedding false data across the user’s Google Workspace devices.

Google’s Response and Mitigation Efforts

SafeBreach reported these findings to Google’s Vulnerability Reward Program on August 17, 2025. By November 14, 2025, Google confirmed the deployment of content classifier updates that effectively countered the described attack methods.

This discovery underscores the importance of robust cybersecurity measures, particularly as smart technology becomes more integrated into daily life. Users are encouraged to stay informed about potential risks and participate in awareness programs like the upcoming webinar on OWASP API Top 10 and WAAP guidance.

Cyber Security News Tags:Android Utilities, context poisoning, Cybersecurity, fake context alignment, Google Gemini, Messaging Apps, prompt injection, SafeBreach, smart home exploitation, Vulnerability

Post navigation

Previous Post: Google Gemini Vulnerability Exposed by Notifications
Next Post: New Malspam Campaign Exploits Google DoubleClick

Related Posts

GhostBat RAT Android Malware With Fake RTO Apps Steals Targeting Indian Users to Steal Banking Data GhostBat RAT Android Malware With Fake RTO Apps Steals Targeting Indian Users to Steal Banking Data Cyber Security News
Security Vulnerability in Composer Exposes Sensitive Files Security Vulnerability in Composer Exposes Sensitive Files Cyber Security News
ChoiceJacking Attack Lets Hackers Compromise Android & iOS Devices via Malicious Charger ChoiceJacking Attack Lets Hackers Compromise Android & iOS Devices via Malicious Charger Cyber Security News
SafePay Ransomware Infected 260+ Victims Across Multiple Countries SafePay Ransomware Infected 260+ Victims Across Multiple Countries Cyber Security News
Beware of GTA 6 Scam Sites Exploiting Gamers Beware of GTA 6 Scam Sites Exploiting Gamers Cyber Security News
Hackers Exploit AI Bot Names to Steal Sensitive Data Hackers Exploit AI Bot Names to Steal Sensitive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark