SafeBreach discovers and helps fix Gemini Android notification vulnerability affecting multiple messaging apps
Summary
SafeBreach researchers discovered a now-fixed vulnerability in Google's Gemini Android feature that could allow malicious notifications from apps like WhatsApp, Slack, SMS, Signal, Instagram, and Messenger to manipulate Gemini's responses, impersonate trusted contacts, trigger connected tools, and poison long-term memory. Google mitigated the issue with server-side content-classifier improvements, and no real-world exploitation was reported.
Source
Key quotes
· 4 pulledSafeBreach identified a now-fixed Gemini Android flaw in the Android Utilities feature that reads and responds to phone notifications.
Crafted alerts from WhatsApp, Slack, SMS, Signal, Instagram, and Messenger could steer Gemini's handling of untrusted notification text.
The same mechanism could poison long-term memory.
Google mitigated the issue using server-side content-classifier improvements, and researchers reported no evidence of real-world exploitation.
You might also wanna read
Google expands testing of persistent Gemini overlay bubble with refreshed gradient design on Android
Google is expanding testing of a persistent Gemini overlay bubble in Android, which allows users to keep their Gemini conversation active ev
Google Gemini is about to control your messages and calls, even if you say no

Google Updates Gemini AI to Better Direct Users to Mental Health Crisis Resources
Google has updated its Gemini AI chatbot to better direct users to mental health resources during crisis situations, particularly for suicid
How Google's Gemini Feature Interacts with WhatsApp and How to Control It
Google has introduced a feature that allows Gemini to access third-party apps like WhatsApp, even when Gemini Apps Activity is turned off. U

Google Launches Gemini AI Desktop App for Mac with Floating Chat Interface
Google is launching a new Gemini AI app for Mac that allows users to interact with the AI assistant directly from their desktop without swit
Google API Keys Security Risk: Public Keys Now Grant Unauthorized Access to Gemini
Google's long-standing policy that API keys for services like Maps and Firebase were not secrets has changed with the introduction of Gemini
trufflesecurity.com·3mo ago