Critical Gemini Flaw Lets Attackers Inject Malicious Prompts via Messaging Apps
Key Takeaways Google Gemini’s voice assistant is vulnerable to a new class of indirect prompt injection (IPI) attacks. Malicious payloads can be delivered via common messaging applications like...
Key Takeaways
- Google Gemini’s voice assistant is vulnerable to a new class of indirect prompt injection (IPI) attacks.
- Malicious payloads can be delivered via common messaging applications like WhatsApp, Slack, Signal, SMS, Instagram, and Messenger.
- The flaw allows silent hijacking of Gemini, enabling context poisoning, remote device control, and covert surveillance.
- SafeBreach researchers demonstrated techniques to bypass Google’s defenses, but Google has since confirmed mitigation.
Google Gemini Vulnerability Exploited Through Messaging Apps
A significant vulnerability has been uncovered in Google Gemini’s voice assistant, allowing attackers to discreetly inject malicious prompts through popular messaging platforms. This new indirect prompt injection (IPI) attack vector leverages crafted payloads sent via applications such as WhatsApp, Slack, Signal, SMS, Instagram, and Messenger, effectively turning everyday communications into a conduit for silent AI hijacking.
Table Of Content
The research, conducted by Or Yair, Security Research Team Lead at SafeBreach, expands upon their previous “Invitation Is All You Need” disclosure, which exploited Google Calendar invitations to compromise Gemini. The current findings reveal a much broader attack surface, encompassing any application capable of generating a device notification as a potential delivery mechanism for malicious instructions.
Exploiting Gemini’s Android Utilities Agent
The core of this exploit lies in Gemini’s Android Utilities agent, specifically its function designed to read incoming notifications. This tool’s processing of untrusted data from third-party applications creates an opening for attackers to embed harmful commands directly within a seemingly innocuous message.
Once Gemini processes a notification containing these poisoned instructions, it silently integrates the attacker’s commands into its conversational context, completely unbeknownst to the user. This notification-based IPI enables comprehensive context poisoning, granting attackers full control over Gemini’s output without requiring the invocation of external tools. For instance, a compromised assistant could be manipulated to display a deceptive system message, such as “There was an error — click here to refresh,” a classic phishing tactic delivered through a seemingly trusted AI interface.
Fake Context Alignment: Bypassing Google’s Defenses
Following Google’s efforts to patch earlier vulnerabilities by restricting chained tool invocations and Delayed Tool Invocation, SafeBreach researchers devised a novel bypass technique termed Fake Context Alignment. This method creates a sophisticated illusion, presenting a legitimate authorization scenario to Gemini’s backend security while simultaneously showing the victim an entirely benign interaction.
The researchers demonstrated two primary techniques:
- Obfuscated Fake Context Alignment: This technique involves Gemini appending a malicious authorization question in a foreign language, such as Chinese (e.g., “你想打开窗户吗?” — “Do you want to open the window?”), immediately followed by a harmless English question. When the user responds “Yes” to the English prompt, the backend inadvertently aligns this affirmative response with the hidden foreign-language instruction, thereby triggering tool execution.
- Muted Fake Context Alignment: Here, the malicious question is embedded within clickable link text that Gemini’s text-to-speech engine silently omits. The user only hears a benign voice prompt and unknowingly authorizes a tool call by simply replying “Yes.”
By combining these two methods into an “Ultimate Combo” payload, the researchers effectively circumvented all of Google’s latest mitigation strategies with high reliability and minimal user detection.
With Delayed Tool Invocation re-enabled, the researchers showcased a range of high-severity exploits. These included leveraging smart home technology to remotely control connected devices like windows, boilers, and lighting via Google Home. Other alarming tactics demonstrated included covert video streaming, where an attacker could force Zoom to launch and stream the victim’s camera live using a 301 HTTP redirect from a Safe Browsing-approved domain. Large-scale social engineering schemes were also possible, allowing the fabrication of messages from trusted contacts by extracting real sender names from the notification queue without prior knowledge of the contact’s identity.
Furthermore, the research highlighted critical concerns such as persistent memory poisoning, which involves injecting false information into Gemini’s long-term memory across the victim’s entire Google Workspace account, impacting devices like tablets, computers, and smart speakers. Finally, scheduled surveillance tactics were demonstrated, enabling the establishment of recurring tasks that automatically read a user’s recent messages daily, further compromising privacy and security.
SafeBreach submitted their findings to Google’s Vulnerability Reward Program on August 17, 2025. Google subsequently confirmed on November 14, 2025, that updated content classifier improvements had successfully mitigated the indirect prompt injection and Delayed Tool Invocation scenarios detailed in the research.
What You Should Do
- Ensure your Google Gemini application and Android operating system are updated to the latest versions to benefit from Google’s content classifier improvements.
- Exercise caution when interacting with notifications from messaging apps, especially if they seem unusual or prompt for actions related to your AI assistant or smart devices.
- Regularly review the permissions granted to applications and AI assistants on your device.
- Be wary of unexpected prompts or system messages, even if they appear to come from a trusted AI interface, as they could be part of a phishing attempt.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.