ended6월 4일· 1 sources
The Blind Spot: Why Google Gemini Treats Messages as Instructions
읽기만 해도 위험: Google Gemini의 숨겨진 구조적 허점
Why it matters
This vulnerability exposes a critical architectural weakness in AI assistants: they cannot reliably distinguish between user data and attacker instructions when consuming untrusted external content. The attack is uniquely dangerous because it bypasses all traditional mobile security defenses without requiring a malicious app, special permissions, or elevated privileges—just carefully crafted text in a notification. The memory poisoning variant is especially concerning, as false context injected into Gemini's long-term memory can persist and affect users long after the initial attack.
1
Sources
+0
24h
—
Growth
5d
Active
Prompt injectionGoogle GeminiNotification hijackingMemory poisoningVoice assistant