WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
ID: 1db8207c-1176-502e-8475-59b54f817034
STIX ID: report--1db8207c-1176-502e-8475-59b54f817034
Feed Name: The Hacker News
SafeBreach researcher Or Yair demonstrated that Gemini's Android Utilities (notification read/reply) could be abused via poisoned notifications to perform privileged actions, spoof spoken messages, control smart-home devices, force app/URL launches (including joining Zoom), and persist attacker-chosen facts in account-level memory; Google deployed server-side content-classifier fixes and the only user mitigations are disabling Gemini's notification access or the Google app's notification control permission.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
