Multiple reports describe a security risk in which “poisoned” notifications from common messaging and chat services could be used to hijack Google Gemini on Android. The scenario does not require a malicious app. Instead, an attacker sends a specially crafted, hostile notification message through services such as WhatsApp, Slack, SMS, Signal, Instagram, or Messenger. When the Android device surfaces that notification and Gemini processes it—particularly in the context of voice assistant features—it may follow attacker instructions.
According to the accounts, the potential outcomes include opening connected windows, generating or altering responses that could appear to come from the victim’s boss, starting or pushing the device into actions such as joining a Zoom call, and manipulating the assistant’s behavior in ways that may affect longer-term memory or future interactions. The reports frame the issue as related to prompt injection through notification content, implying that the assistant may treat untrusted notification text as legitimate instructions.
The articles emphasize that the mechanism targets the way Gemini integrates with Android notifications, raising concerns about how hostile content could be translated into high-impact assistant actions.