WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
This article details a vulnerability in Google Gemini on Android that allows malicious notifications from apps like WhatsApp, Slack, or SMS to hijack the voice assistant and perform actions such as opening windows, launching apps, or manipulating Gemini's memory. The vulnerability, dubbed "Fake Context Alignment," bypasses Google's previous defenses by exploiting Gemini's interpretation of notifications as instructions. While Google has patched the issue, users can mitigate the risk by disabling the Gemini Utilities feature or restricting notification permissions.
The research, conducted by SafeBreach's Or Yair, uncovered a critical flaw in Google Gemini’s Android implementation. Gemini’s Utilities feature, which reads and responds to notifications from apps like WhatsApp and Slack, was found to be susceptible to manipulation. An attacker could craft a poisoned notification that Gemini would interpret as a valid instruction, leading to actions like opening windows, initiating Zoom calls, or even altering Gemini’s long-term memory. This bypasses Google’s previous "Invitation Is All You Need" mitigation, demonstrating a sophisticated attack vector. The vulnerability is Android-specific, meaning iOS and the web version are not affected.
