Gemini Voice Assistant Hijacked via Messaging Notifications
Google Gemini voice assistant vulnerable to hijacking via messaging notification prompt injections.
Summary
SafeBreach researchers discovered a critical vulnerability in Google's Gemini voice assistant that allowed attackers to inject malicious commands through messaging notifications from apps like WhatsApp, Slack, and SMS. The attack, termed Fake Context Alignment, could enable threat actors to control smart home devices, initiate video calls, craft spoofed messages, and establish persistent control over the assistant. Google patched the vulnerability in mid-November 2025 after disclosure in August 2025.
Full text
SafeBreach researchers uncovered a critical vulnerability in Google’s Gemini voice assistant that could have allowed attackers to hijack the AI using indirect prompt injections delivered through ordinary messaging notifications. The cybersecurity firm previously discovered a calendar invite attack targeting Gemini and Google Workspace that an attacker could have used to conduct spam and phishing, delete calendar events, learn the victim’s location, remotely control home appliances, and exfiltrate emails. Building on that research, SafeBreach discovered a new attack class named Fake Context Alignment. It was disclosed to Google in August 2025 and it was patched in mid-November 2025 with content classifier improvements, but the security firm disclosed its details this week to raise awareness about the persistent risks of prompt injection attacks and to encourage stronger defenses against context manipulation. The Fake Context Alignment attack works by exploiting notifications from popular apps such as WhatsApp, Slack, and SMS, which silently inject malicious instructions into Gemini’s conversation context without the user’s knowledge. Researchers demonstrated techniques such as embedding hidden commands in foreign languages or in muted hyperlinks that the assistant processes but does not read aloud when the user instructs it to read their messaging notifications, effectively bypassing Google’s safeguards.Advertisement. Scroll to continue reading. The vulnerability was especially concerning in hands-free scenarios, such as driving, where users rely heavily on voice interactions with Gemini. This method enabled attackers to trigger dangerous actions, including controlling smart home devices via Google Home, starting Zoom video calls, crafting deceptive messages that appear to come from trusted contacts, and even establishing persistent control by poisoning the AI assistant’s long-term memory. “This research demonstrates that as LLM-powered assistants gain deeper integration into our devices and daily lives, the attack surface expands exponentially. Notification-based attacks prove that indirect prompt injections can be reliably executed through highly trusted, everyday communication channels,” SafeBreach said in a blog post. It added, “Organizations and vendors must move beyond localized mitigations and rethink how AI systems parse trust, context, and cross-channel permissions to ensure user safety.” SafeBreach has published videos showing the Zoom and Google Home attacks in action. Related: Security of 100 AI Agents Tested and Ranked – What You Need to Know Related: Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks Related: Anthropic Expanding Mythos Access to 150 New Organizations Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Hackers Target Global Stock Exchange in Espionage OperationMicrosoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure BacklashAndroid Update Patches Exploited Zero-Day, 123 Other VulnerabilitiesAnthropic Expanding Mythos Access to 150 New OrganizationsOracle WebLogic Vulnerability Exploited in the WildDashlane Brute-Force Attack Leads to Limited Encrypted Vault DownloadsVulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance RateRomanian Hacker Sentenced to Prison in US for Selling Access to State Network Latest News Mirasvit Vulnerability Exploited to Execute Code on Magento ServersChinese Cybercrime Group in Spotlight for Record Campaign PaceOver 1.4 Million Accounts Disrupted in Cybercrime CrackdownCisco Warns of Available PoC for Critical Unified CM VulnerabilityVS Code Vulnerability Allows One-Click GitHub Token TheftCoralogix Raises $200M at $1.6B Valuation to Scale AI Observability PlatformKirki, Burst Statistics WordPress Plugin Flaws in Attackers’ CrosshairsSecurity of 100 AI Agents Tested and Ranked – What You Need to Know Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register Virtual Roundtable: CISO Forum 2026 Mid-Year Review June 10, 2026 Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks. Register People on the MoveCyera has appointed Naveen Palavalli as Chief Marketing Officer.Connie Devine has been promoted to Chief Information Security Officer at Phillips 66.Jeff Lunglhofer becomes Chief Security Officer at Coinbase, replacing Philip Martin.More People On The MoveExpert Insights The Zero-Knowledge Threat Actor and the End of Responsible Disclosure AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. (Etay Maor) Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email