Google Gemini Android Bug Patched After Hijack

SkimNews Take
The ease of exploiting notification permissions on Android means even a seemingly secure AI assistant can be leveraged for malicious actions without direct user interaction.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- SafeBreach researcher Or Yair demonstrated that a malicious notification from apps such as WhatsApp, Slack, SMS, Signal, Instagram, or Messenger can hijack Google Gemini’s voice assistant on Android, causing it to open windows, fake messages, launch Zoom calls, or modify its long‑term memory.
- Google Gemini’s Android Utilities feature reads notification text as actionable instructions, a behavior Yair called an “effectively infinite” attack surface because any notification can be weaponized.
- Google applied a patch after the vulnerability was disclosed, and SafeBreach has not assigned a CVE, with no evidence that the technique has been used in the wild.
- Fake Context Alignment is the name Yair gave to the bypass, which uses obfuscated or muted prompts to trick Gemini’s security check, allowing unauthorized actions despite prior mitigations.
- iOS and the web version of Gemini lack the Utilities feature, so the hijack vector is limited to Android devices.
Why it matters: Android users of Gemini lose security as notifications become a weaponized entry point; Google must allocate resources to patch and harden its assistant, while attackers gain a new, app‑less exploit vector.
Ask SkimNews



