WhatsApp Messages on Android Expose New Gemini AI Security Risk

WhatsApp Messages on Android Expose New Gemini AI Security Risk

The Neuron featured image about Gemini AI security risk.

Image: The Neuron

Written By
Grant Harvey
Grant Harvey
Jun 4, 2026
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Here's a scenario: someone sends you a normal-looking WhatsApp message. You never click anything weird. You never type a suspicious command. But your AI assistant, Google Gemini, reads the notification, follows hidden instructions buried inside it, and quietly exfiltrates your data.

That's exactly what SafeBreach Labs researchers just demonstrated. This is their second time breaking Gemini this way. Their previous research weaponized Google Calendar invites against it.

The attack type is called indirect prompt injection: hiding malicious commands inside content the AI reads, rather than typing them directly. The novel trick here is a technique called "Fake Context Alignment," which makes attack instructions appear to be a legitimate part of your ongoing conversation and is specifically designed to bypass Google's existing defenses against this kind of attack.

Here's what happened

  • Gemini's Android agent reads incoming notifications from messaging apps to give context-aware responses
  • Researchers embedded hidden instructions inside crafted messages; the attack works across WhatsApp, Slack, Signal, SMS, Instagram, and Messenger
  • Gemini followed the attacker's commands silently, with no alert to the user
  • Five threat categories were demonstrated: data theft, unauthorized actions, phishing relay, account takeover prep, and silent surveillance
  • Even without Gemini having external tool access, the poisoned context alone lets attackers make Gemini deliver fake system messages, turning a trusted AI interface into a phishing launcher

The researchers disclosed to Google before publishing. Google's layered defense page acknowledges indirect prompt injection as a known threat class with active mitigations. The SafeBreach research demonstrates those mitigations were bypassed.

Why this matters

The attack surface isn't a bug in one app. It's the design of AI assistants' operation. Any notification Gemini reads from any app is now a potential delivery channel. The more access your assistant has, the bigger the blast radius.

Our take

Google has defenses. They got bypassed twice by the same team. That's the uncomfortable part. The fix isn't panic; it's permission hygiene. Audit what Gemini can access, and disable anything you don't actively use. Here's Google's own guidance on how their defenses work, worth reading to understand what's protected and what isn't. The next researcher is already looking.

Editor’s note: This content originally ran in the newsletter of our sister publication, The Neuron. To read more from The Neuron, sign up for its newsletter here.

Grant Harvey

Grant Harvey is the Lead Writer of The Neuron, where he continues to lead the publication's daily coverage of AI news, tools, and trends.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.