Close Menu
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
Home » Malicious WhatsApp, Slack Alerts Could Have Exposed Millions of Android Users
Gaming

Malicious WhatsApp, Slack Alerts Could Have Exposed Millions of Android Users

By June 16, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

A routine phone notification could have become an attack path for Google Gemini on Android, according to new research from SafeBreach.

The now-mitigated issue involved crafted alerts from WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. SafeBreach said the alerts could influence how Gemini handled notification text, alter spoken responses, impersonate trusted contacts, trigger connected tools, and poison long-term memory.

Google addressed the issue with server-side content-classifier improvements. Researchers found no evidence of real-world exploitation.

Researchers found a notification-based prompt injection path

SafeBreach Labs said its researchers found the issue while testing Gemini’s Android Utilities feature, which can read and respond to phone notifications. The flaw affected how Gemini processed untrusted notification text from messaging and social apps.

The research was published on June 3 by Or Yair, security research team lead at SafeBreach. It followed the company’s earlier “Invitation Is All You Need” work, which showed how malicious Google Calendar invites could manipulate Gemini.

“The main purpose of Fake Context Alignment is to create a dual illusion: presenting a legitimate authorization scenario to Gemini’s behind-the-scenes security mechanisms, while presenting a completely different, benign scenario to the victim,” Yair wrote in the SafeBreach report.

The Hacker News reported that the attack did not require a malicious app on the victim’s phone. An attacker only needed to send a crafted notification that Gemini might later summarize or read aloud.

Fake Context Alignment bypassed newer guardrails

Google has already added protections after the earlier calendar-based research, but SafeBreach said Yair found a new bypass called Fake Context Alignment.

The technique created two versions of the same interaction. One looked like a legitimate consent to Gemini’s security checks. The other one sounded harmless to the user.

In one example, Gemini displayed or processed an authorized question in a foreign language while asking the user an unrelated English question aloud. If the user answered “yes,” Gemini could interpret it as approval of the hidden action.

According to Dark Readingthe technique could support social engineering, smart home control, unauthorized video streams, and long-term memory poisoning. Yair told Dark Reading, “We do need to treat all external input as not trusted because all external input is a potential instruction.”

Google says the issue has been fixed

SafeBreach noted that Google has already addressed the issue. The fix was made on Google’s side, so users do not need to install a specific Gemini app update to receive the mitigation.

SafeBreach further clarified that no CVE was listed for the issue and that there was no evidence the technique had been used in the wild.

On Android, users can limit exposure by disabling Gemini’s Utilities app in the Connected Apps settings or by turning off the Google app’s “Notification read, reply & control” permission. Those settings control whether Gemini can read and respond to notifications.

For organizations, the finding serves as a reminder that AI assistant permissions can have security implications beyond the assistant itself. Notification access, connected app permissions, and policies for AI tools on managed devices all affect how much outside content an assistant can process or act on.

See how attackers used a Meta AI support exploit to hijack the Obama White House Instagram account.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Rockstar Co-Founder Dan Houser Says if People Want Physical Game Releases Then Companies Should Provide It

July 26, 2026

With Doomsday Approaching, Grab A Cheap Marvel Tokon: Fighting Souls Steam Key With This Preorder Deal

July 25, 2026

Tides of War’ Adds Cross-Server Battles in Latest Empire Invasion Update – TouchArcade

July 24, 2026
Leave A Reply Cancel Reply

Comment moderation is enabled. Your comment may take some time to appear.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest
  • Samsung Galaxy Z Fold 8 review: a shot in the arm for the foldables market August 3, 2026
  • Best MagSafe wallets of 2026: Expert tested and reviewed August 3, 2026
  • ‘It’s without a doubt one of the least detrimental privacy-focused solutions to your mobile experience’: I spent a month testing GrapheneOS — and it almost made me ditch my Android phone entirely July 30, 2026
  • Low-power AI could define the next era of global innovation July 30, 2026
  • NYT Strands hints and answers for Wednesday, July 29 (game #878) July 29, 2026
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from Techzlab.

Tags
AI Amazon Anthropic Apple artificial intelligence ChatGPT cybersecurity data centers defense tech Donald Trump electric vehicles Elon Musk evergreens EVs Exclusive Fintech gemini Google Grok In Brief India Layoffs Meta Microsoft Mythos nvidia nvidia gtc Nvidia GTC 2026 Openai Perplexity Polymarket Redwood Materials sam altman Sequoia Capital siri social media Softbank SpaceX Spotify Tesla Tim Cook Truecaller Uber Windows X
Archives
Quick Link
  • Apps (403)
  • From the Editor (4)
  • Gaming (382)
  • Laptops (405)
  • Latest in Tech (404)
  • Mobiles (405)
  • Money (228)
  • Tech Insights (406)
Don't miss

Best MagSafe wallets of 2026: Expert tested and reviewed

August 3, 2026

I tested a premium Linux laptop that’s as light as it is powerful – here’s why I love it

July 29, 2026

Is the Electric Trike the Next Big Thing in Shared Micromobility?

July 28, 2026
Follow us
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 Techzlab.com Designed and Developed by WebExpert.
  • Home
  • From the Editor
  • Money
  • Privacy Policy
  • Contact

Type above and press Enter to search. Press Esc to cancel.