Google fixes Gemini Android flaw from malicious notifications

A vulnerability in Google Gemini on Android allowed crafted notifications from apps like WhatsApp and Slack to manipulate the AI's responses and connected tools. The issue, discovered by SafeBreach, has been addressed through server-side changes.

SafeBreach researchers identified the flaw while testing Gemini’s Android Utilities feature, which reads and responds to phone notifications. The problem enabled prompt injection attacks using alerts from messaging and social apps including WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. The technique, called Fake Context Alignment, created dual scenarios that bypassed security checks. One appeared legitimate to Gemini while presenting a benign version to the user. Or Yair, security research team lead at SafeBreach, published the findings on June 3. Google resolved the issue with server-side content-classifier improvements. No evidence of real-world exploitation was found, and no app update was required for users. Researchers noted that the attack did not need a malicious app on the device. Users can reduce risk by disabling Gemini’s Utilities app or the Google app’s notification permissions. The discovery follows earlier research on calendar-based attacks against the AI.

संबंधित लेख

Illustration of a person checking their phone for a spoofed call warning on Android, highlighting Google's new deepfake detection feature.
AI द्वारा उत्पन्न छवि

Google adds detection for spoofed calls to Android phones

AI द्वारा रिपोर्ट किया गया AI द्वारा उत्पन्न छवि

Google is rolling out a new feature to Android devices that detects impersonation scams involving spoofed calls. The update targets the rising threat of AI-generated deepfake voices in financial fraud. It begins deploying this month on phones running Android 12 and higher.

Google has been quietly installing a 4GB AI model called Gemini Nano onto some Chrome browsers without notifying users. Computer scientist Alexander Hanff raised the issue after discovering the file on his devices. The company says the model supports on-device features like scam detection and has provided ways to disable it.

AI द्वारा रिपोर्ट किया गया

Google has rolled out enhancements to its Google Home app, improving camera navigation and controls with Gemini AI integration. The update also brings Gemini 3.1 to the voice assistant for early access users, enabling better handling of complex commands. New automation options expand smart home capabilities.

Google has begun rolling out a new 'Skills' feature in its Chrome browser on desktop, enabling users to save and quickly reuse custom Gemini AI prompts. The update makes it easier to repeat tasks like calculating protein in recipes or comparing products across tabs. Skills sync across devices when signed into a Google account and include a library of premade prompts.

AI द्वारा रिपोर्ट किया गया

A banking trojan has resurfaced on Android devices, posing as popular apps including TikTok and various streaming services.

यह वेबसाइट कुकीज़ का उपयोग करती है

हम अपनी साइट को बेहतर बनाने के लिए विश्लेषण के लिए कुकीज़ का उपयोग करते हैं। अधिक जानकारी के लिए हमारी गोपनीयता नीति पढ़ें।
अस्वीकार करें