Notification-Based Prompt Injection Gave Attackers Complete Control of Google Gemini on Android

ATTACKER WhatsApp/SMS Slack / Signal any notification GEMINI Android Assistant Utilities / Notif. Agent reads all notification text iOS/web: unaffected FAKE CONTEXT ALIGNMENT auth bypass multilingual obfuscation + TTS muting SafeBreach / Or Yair MEMORY POISON account-level persist all devices affected 8 PM daily surveillance DEVICE CONTROL Google Home / IoT forced Zoom stream IP geolocation / DL disclosed Aug 17 2025 — server-side patch Nov 14 2025 — no CVE assigned
Zero
Malicious Apps Required
89 Days
Disclosure to Patch
Infinite
Attack Surface (Any Notification)
Account-Level
Memory Poisoning Persistence
TL;DR
  • What: Google Gemini's Android notification-reading agent treated incoming notification text as executable instructions, letting any app that can push notifications deliver prompt-injection payloads — no malicious app, no CVE.
  • Impact: Attackers could control Google Home devices, force victims into Zoom calls, geolocate them via redirect, and permanently poison Gemini's account-level memory to enable recurring surveillance.
  • Fix / mitigation: Google deployed a server-side content classifier on Nov 14, 2025 (89 days after disclosure); users can also disconnect Gemini's Utilities app or revoke the "Notification read, reply & control" Android permission.
  • Who's at risk: Android users with Google Gemini's Utilities/notification-reading feature enabled; iOS and web versions are unaffected.

Google Gemini's Android voice assistant could be completely hijacked through a single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger. The vulnerability allowed attackers to control smart home devices, fake messages from trusted contacts, force victims into Zoom calls, and persistently poison the AI's long-term memory—all without requiring any malicious app on the target device.

SafeBreach researcher Or Yair disclosed the vulnerability to Google's Vulnerability Reward Program on August 17, 2025. Google confirmed mitigation through server-side content-classifier improvements on November 14, 2025. No CVE was assigned, and no evidence exists of exploitation in the wild. The attack vector exploited Gemini's Utilities feature, which reads and replies to Android notifications—functionality not available on iOS or web versions.

Attack Vector: Treating Notifications as Instructions

The core vulnerability resided in how Gemini's notification-reading agent processed text. The agent treated notification content as actionable instructions rather than simple data to be displayed. Any application or service capable of pushing notifications to an Android device could deliver a payload, creating what Yair described as an "effectively infinite" attack surface.

At its simplest, attackers could rewrite Gemini's spoken output. A notification could inject instructions causing the assistant to claim "your manager asked you to upload the docs to this Drive folder" while the victim was driving and unable to verify the screen. More sophisticated attacks could grab the first real sender name from the notification queue and pin fabricated messages on legitimate contacts, making social engineering attacks nearly undetectable through audio alone.

Fake Context Alignment: Bypassing Google's Security Checks

This research followed SafeBreach's earlier "Invitation Is All You Need" work exploiting Google Calendar invites. After that disclosure, Google hardened Gemini against indirect prompt injection by implementing authorization checks: when a "Yes" authorizes a sensitive action, the system weighs both the user's reply and Gemini's last output to validate the authorization makes contextual sense. Direct injection attempts failed consistently against this defense.

Yair's bypass, named Fake Context Alignment, ran two simultaneous illusions—one for the security check, one for the human victim. The technique used two primary methods:

Voice Interface Exploitation

The attack is particularly dangerous in hands-free scenarios. Drivers, people with visual impairments, or users multitasking rely entirely on audio output. When Gemini speaks a benign English question while the screen shows a sensitive authorization in another language, victims have no way to detect the discrepancy through the voice interface alone.

Impact Scope: Smart Homes to Persistent Memory Poisoning

Once past authorization checks, attackers gained extensive control capabilities:

No User Action Required

SafeBreach emphasized that their domain never redirected to Zoom during responsible disclosure—the redirect demonstration ran on a local server on the test device. However, the technique proved that trusted domains could be leveraged for redirection attacks once initial trust was established.

Mitigation and Timeline

Google treated the disclosure as high priority. The 89-day window from August 17 disclosure to November 14 confirmation represents relatively rapid response for a complex AI security issue. Google's mitigation focused on content-classifier improvements to detect notification-based injections and block the Delayed Tool Invocation bypass technique.

Critically, the fix deployed server-side. No app updates are required, and users have no patch to install or verify. This approach enables rapid deployment but removes visibility into whether specific devices or accounts received protection. Organizations managing Android fleets cannot audit patch status through traditional mobile device management tools.

User Controls and Recommendations

The only user-accessible control is disabling Gemini's notification access entirely. Organizations can enforce this through two methods:

This represents an all-or-nothing choice. Gemini cannot selectively read notifications from trusted apps while blocking others. Organizations must weigh the productivity benefits of AI-assisted notification management against the risk that any notification source becomes an injection vector.

Broader Implications for AI Agent Security

This vulnerability exposes fundamental challenges in securing AI agents that bridge multiple data sources and execution contexts. Gemini's design treats user notifications, calendar invites, and direct commands as equivalent input streams. When an AI cannot reliably distinguish between user intent and external data, every input channel becomes a potential command injection vector.

The Fake Context Alignment technique demonstrates that authorization checks based on conversational context can be gamed through multilingual obfuscation and interface mismatches between visual and audio output. As AI assistants gain deeper system integration—controlling smart homes, accessing corporate tools, managing financial accounts—the attack surface expands proportionally. Each new capability increases the value of successful prompt injection.

Security teams should recognize that this vulnerability class extends beyond Google Gemini. Any AI agent that processes untrusted input while holding elevated permissions faces similar risks. The notification vector is particularly concerning because it requires no user interaction beyond normal device usage. Unlike phishing, which demands the victim click a link or open an attachment, notification-based injection executes when the AI assistant simply reads incoming messages as part of its designed workflow.

Organizations deploying AI assistants should inventory what data sources their agents access, what permissions they hold, and whether untrusted input can reach decision-making contexts. Server-side content filtering, as Google deployed, provides defense but cannot be verified by end users or administrators. Traditional security controls—application allowlisting, network segmentation, least privilege—apply imperfectly to AI agents that require broad access to function as designed.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us