Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Gemini Voice Assistant Hijacked via Messaging Notifications

Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls.

Gemini

SafeBreach researchers uncovered a critical vulnerability in Google’s Gemini voice assistant that could have allowed attackers to hijack the AI using indirect prompt injections delivered through ordinary messaging notifications.

The cybersecurity firm previously discovered a calendar invite attack targeting Gemini and Google Workspace that an attacker could have used to conduct spam and phishing, delete calendar events, learn the victim’s location, remotely control home appliances, and exfiltrate emails.

Building on that research, SafeBreach discovered a new attack class named Fake Context Alignment

It was disclosed to Google in August 2025 and it was patched in mid-November 2025 with content classifier improvements, but the security firm disclosed its details this week to raise awareness about the persistent risks of prompt injection attacks and to encourage stronger defenses against context manipulation.

The Fake Context Alignment attack works by exploiting notifications from popular apps such as WhatsApp, Slack, and SMS, which silently inject malicious instructions into Gemini’s conversation context without the user’s knowledge. 

Researchers demonstrated techniques such as embedding hidden commands in foreign languages or in muted hyperlinks that the assistant processes but does not read aloud when the user instructs it to read their messaging notifications, effectively bypassing Google’s safeguards.

Advertisement. Scroll to continue reading.

The vulnerability was especially concerning in hands-free scenarios, such as driving, where users rely heavily on voice interactions with Gemini.

This method enabled attackers to trigger dangerous actions, including controlling smart home devices via Google Home, starting Zoom video calls, crafting deceptive messages that appear to come from trusted contacts, and even establishing persistent control by poisoning the AI assistant’s long-term memory. 

“This research demonstrates that as LLM-powered assistants gain deeper integration into our devices and daily lives, the attack surface expands exponentially. Notification-based attacks prove that indirect prompt injections can be reliably executed through highly trusted, everyday communication channels,” SafeBreach said in a blog post. 

It added, “Organizations and vendors must move beyond localized mitigations and rethink how AI systems parse trust, context, and cross-channel permissions to ensure user safety.”

SafeBreach has published videos showing the Zoom and Google Home attacks in action. 

Related: Security of 100 AI Agents Tested and Ranked – What You Need to Know

Related: Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks

Related: Anthropic Expanding Mythos Access to 150 New Organizations

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Cyera has appointed Naveen Palavalli as Chief Marketing Officer.

Connie Devine has been promoted to Chief Information Security Officer at Phillips 66.

Jeff Lunglhofer becomes Chief Security Officer at Coinbase, replacing Philip Martin.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.