Google fixes Gemini Android flaw from malicious notifications

A vulnerability in Google Gemini on Android allowed crafted notifications from apps like WhatsApp and Slack to manipulate the AI's responses and connected tools. The issue, discovered by SafeBreach, has been addressed through server-side changes.

SafeBreach researchers identified the flaw while testing Gemini’s Android Utilities feature, which reads and responds to phone notifications. The problem enabled prompt injection attacks using alerts from messaging and social apps including WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. The technique, called Fake Context Alignment, created dual scenarios that bypassed security checks. One appeared legitimate to Gemini while presenting a benign version to the user. Or Yair, security research team lead at SafeBreach, published the findings on June 3. Google resolved the issue with server-side content-classifier improvements. No evidence of real-world exploitation was found, and no app update was required for users. Researchers noted that the attack did not need a malicious app on the device. Users can reduce risk by disabling Gemini’s Utilities app or the Google app’s notification permissions. The discovery follows earlier research on calendar-based attacks against the AI.

Mga Kaugnay na Artikulo

Illustration of a person checking their phone for a spoofed call warning on Android, highlighting Google's new deepfake detection feature.
Larawang ginawa ng AI

Google adds detection for spoofed calls to Android phones

Iniulat ng AI Larawang ginawa ng AI

Google is rolling out a new feature to Android devices that detects impersonation scams involving spoofed calls. The update targets the rising threat of AI-generated deepfake voices in financial fraud. It begins deploying this month on phones running Android 12 and higher.

Google has been quietly installing a 4GB AI model called Gemini Nano onto some Chrome browsers without notifying users. Computer scientist Alexander Hanff raised the issue after discovering the file on his devices. The company says the model supports on-device features like scam detection and has provided ways to disable it.

Iniulat ng AI

Google has rolled out enhancements to its Google Home app, improving camera navigation and controls with Gemini AI integration. The update also brings Gemini 3.1 to the voice assistant for early access users, enabling better handling of complex commands. New automation options expand smart home capabilities.

Google has begun rolling out a new 'Skills' feature in its Chrome browser on desktop, enabling users to save and quickly reuse custom Gemini AI prompts. The update makes it easier to repeat tasks like calculating protein in recipes or comparing products across tabs. Skills sync across devices when signed into a Google account and include a library of premade prompts.

Iniulat ng AI

A banking trojan has resurfaced on Android devices, posing as popular apps including TikTok and various streaming services.

Gumagamit ng cookies ang website na ito

Gumagamit kami ng cookies para sa analytics upang mapabuti ang aming site. Basahin ang aming patakaran sa privacy para sa higit pang impormasyon.
Tanggihan