Notification Summaries Can Become an Action Channel
A read-only notification summary is not read-only if the assistant can act on what it reads. Hidden instructions inside a message can ride along as trusted context, so Gemini may carry out actions the user never saw or approved.
SafeBreach showed this against Google Gemini’s voice assistant by hiding malicious text in message notifications, extending its earlier calendar-invite prompt injection work. Google has since pushed content-classifier updates, and there is still no evidence of in-the-wild use.
The risk reaches any assistant that summarizes email or chat and can open streams, control devices, or draft replies. In those systems, the prompt is part of the control path, not just a convenience feature.