logo

Fake Context Alignment: The Attack That Made Gemini Obey Strangers Through Your Notifications

ID: 55c066a5-4ce3-516a-a1e8-7867e025f8f0

STIX ID: report--55c066a5-4ce3-516a-a1e8-7867e025f8f0

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Pierluigi Paganini

...
...

SafeBreach Labs disclosed a proof-of-concept attack named "Fake Context Alignment" that leverages notification text (including hidden foreign-language text and muted hyperlinks) to perform indirect prompt injection against Google Gemini. The technique bypasses delayed tool-invocation checks and can trigger actions such as controlling smart-home devices, joining Zoom calls, and creating persistent tasks that propagate across devices; Google was notified and updated classifiers to block the demonstrated techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.