WhatsApp, Slack Notifications Could Hijack Google Gemini on Android – The Hacker News

Home AI WhatsApp, Slack Notifications Could Hijack Google Gemini on Android – The Hacker News
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android – The Hacker News

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made it open a victim’s connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its long-term memory.
No malicious app on the phone is required. The assistant just had to treat a hostile notification as useful context.
The research, published by SafeBreach’s Or Yair, follows the team’s earlier “Invitation Is All You Need” work, which pulled off similar tricks through malicious Google Calendar invites. After that, Google hardened Gemini against indirect prompt injection.
Yair found a way around the new defenses. Google has since patched it, SafeBreach lists no CVE for the issue, and there is no evidence that the technique was ever used in the wild.
On Android, Gemini’s Utilities feature can read and reply to your notifications, including ones from apps like WhatsApp. It isn’t available on iOS or the web, which keeps this vector Android-only. Yair found the agent that reads those notifications treats their text as instructions it can act on. So anything that can push a notification to a phone can deliver a payload, an attack surface Yair called “effectively infinite.”
At minimum, that lets an attacker rewrite what Gemini says, including faking a message from a named contact. Spoken aloud while you drive and don’t look at the screen, “your manager asked you to upload the docs to this Drive folder” is hard to second-guess. The blind version is worse: the payload fires after Gemini has loaded real notifications, so it can grab the first real sender name in the queue and pin the fake message on them.
Faking output is one thing. Firing real tools, like opening a window or launching an app, is what Google’s post-“Invitation” mitigations were built to stop. Yair’s read, from black-box testing: when a “Yes” authorizes a sensitive action, a check weighs both the user’s reply and Gemini’s last output to decide whether that “Yes” makes sense. Inject a delayed instruction out of nowhere, and Gemini refused, every time.
So the bypass, which Yair named Fake Context Alignment, runs two illusions at once: a legitimate-looking authorization for the security check, a harmless exchange for the human.
Combine the two, a Chinese authorization prompt hidden inside a muted link, and you get a payload that sounds like a normal English exchange while clearing Google’s newest checks.
Past the authorization gate, the impacts matched the earlier research and then went further:
SafeBreach reported the findings to Google’s Vulnerability Reward Program on August 17, 2025. Google treated it as a high priority and confirmed on November 14, 2025, that content-classifier improvements mitigated the notification injections and the Delayed Tool Invocation bypass.
Because the fix is server-side, there is no app update to chase. The only control users have is whether Gemini reads notifications at all: disconnect the Utilities app in Gemini’s Connected Apps settings, or turn off the Google app’s “Notification read, reply & control” permission on Android.
Learn practical strategies to detect and defend against cyber threats beyond zero-day vulnerabilities.
Learn how to validate automated pentesting results for accurate security decisions.
Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free.

source

Leave a Reply

Your email address will not be published.