logo

Hackers Exploit Google Gemini Flaw Using Malicious Messages from WhatsApp, Slack, and SMS

ID: d1ab602c-ea78-53f5-8279-22ab689af531

STIX ID: report--d1ab602c-ea78-53f5-8279-22ab689af531

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Divya

...
...

SafeBreach Labs disclosed a notification-based indirect prompt-injection vulnerability in Google’s Gemini Android assistant that allows attackers to inject hidden instructions via notifications (e.g., WhatsApp, Slack, SMS). Using techniques called Fake Context Alignment (obfuscated foreign-text and muted clickable links), researchers showed attackers can bypass Google’s prior mitigations to trigger tool calls, control smart-home devices, open URLs or apps, and abuse memory/scheduling for persistent effects; Google implemented classifier and security updates by November 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.