WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

Google Gemini’s voice assistant on Android could have been taken over by a single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger, causing it to open a victim’s connected windows, pretend to be a message from their boss, force the phone into a Zoom call, or subtly contaminate its long-term memory.

It is not necessary to have any malicious apps on the phone. All the assistant needed to do was handle a hostile notification as helpful context.

The study, released by Or Yair of SafeBreach, comes after the team’s previous “Invitation Is All You Need” work, which used malicious Google Calendar invites to carry off similar scams. Google then strengthened Gemini’s defenses against indirect quick injection.

Yair managed to get past the new barriers. There is no proof that the method was ever employed in the wild, SafeBreach does not specify a CVE for the problem, and Google has since patched it.

Notifications from apps like WhatsApp can be read and responded to using Gemini’s Utilities feature on Android. This vector is exclusive to Android because it isn’t accessible on iOS or the internet read more about WhatsApp Slack Notifications Could Hijack Google Gemini on Android

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *