Google Gemini Android Notification Prompt Injection Vulnerability

Prompt Injection Google Gemini Android Notification Abuse
Overview
Security researchers discovered a vulnerability in Google Gemini on Android that allowed malicious notifications from apps such as WhatsApp, Slack, Signal, Messenger, and SMS to manipulate the AI assistant through indirect prompt injection. Attackers could craft notification content that Gemini interpreted as commands instead of plain text.

Technical Specifications
| Attribute | Details |
|---|---|
| Vulnerability Type | Indirect prompt injection via Android notifications |
| Affected Service | Google Gemini on Android (Utilities functionality) |
| Affected Inputs | Notifications from WhatsApp, Slack, Signal, Messenger, SMS, and similar apps |
| Root Cause | Unsafe interpretation of untrusted notification content as executable assistant context/commands |
| Bypass Technique | Fake Context Alignment to evade contextual safeguards |
| Abuse Methods | Hidden hyperlinks, multilingual prompts, invisible instruction embedding |
| User Interaction | Voice confirmation or assistant interaction can unintentionally approve malicious actions |
| Malware Requirement | None required |
| Primary Risk | Unauthorized assistant actions and manipulation of AI trust boundaries |
| CVE ID | Not publicly assigned in referenced reporting |
Affected Products
- Android devices using Google Gemini with notification-processing Utilities features
- Users receiving attacker-crafted notifications through messaging and social apps
- High-risk hands-free usage contexts where voice confirmations are used quickly
Attack Scenario
- An attacker sends a crafted message through WhatsApp, Slack, SMS, or another messaging platform.
- The malicious notification appears on the victim's Android device.
- Gemini processes or reads the notification content.
- Hidden instructions manipulate Gemini into performing unauthorized actions.
- The victim unknowingly confirms the action through voice interaction or assistant prompts.
Impact
- Unauthorized assistant-triggered actions can alter expected device and app behavior
- Manipulation of AI memory and contextual state can influence later assistant decisions
- Trust boundaries between user intent and assistant execution are weakened
- Increased phishing and social engineering effectiveness through AI-mediated interactions
- Risk of exposing sensitive contextual information through misleading assistant responses
- Potential misuse of assistant workflows to steer users to attacker-controlled destinations
- Unwanted app launches and automated actions can disrupt normal user workflows
- Joining meetings or triggering actions unexpectedly can interfere with communications reliability
- Repeated abuse scenarios can reduce confidence and safe usability of assistant features
Mitigations
Immediate Actions
- Disable Gemini notification access if unnecessary
- Keep Android and Gemini services updated
- Carefully review on-screen prompts before confirming assistant actions
Short-term Measures
- Limit AI assistant permissions to only required capabilities
- Avoid granting excessive automation permissions to AI assistants
- Strengthen mobile configuration baselines for assistant and notification permissions
Resources
Open-Source Reporting
- WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
- Hackers could use poisoned WhatsApp and Slack notifications to take over your Google Gemini – and make it work on their behalf | TechRadar
- Google Gemini security flaw lets hackers hijack your Android phone via WhatsApp — what you need to know | Tom's Guide
- Malicious WhatsApp, Slack Alerts Could Have Exposed Millions of Android Users
- WhatsApp, Slack Notifications Could Hijack Google Gemini on Android — h4x.lat
Last Updated: June 7, 2026