Sicurezza AI · Attacco basato su AI
Un riepilogo delle notifiche in sola lettura non è in sola lettura se l'assistant può agire su ciò che legge. Istruzioni nascoste all'interno di un messaggio possono viaggiare come trusted context, così Gemini può eseguire azioni che l'utente non ha mai visto o approvato.
3 fonti · 4 giu
SecurityWeek
Gemini Voice Assistant Hijacked via Messaging Notifications
Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls.
originaleThe Hacker News
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
Poisoned Android notifications could hijack Google Gemini’s voice assistant without a malicious app.
originaleDark Reading
Malicious Notifications Could Trick Google Gemini Users
A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.
originalePart of the PlainSec briefing for 2026-06-03
Every edition of this story: Le Notification Summary Possono Diventare un Canale di Azione