A single malicious notification could get Gemini to control your phone and home.

Author: Published 4 min de lectura 159 reading

The images in this article were generated with artificial intelligence. How we publish

A SafeBreach researcher showed that, until Google's correction, a single malicious notification sent to an Android phone could manipulate the voice assistant Gemini and cause from false messages to the silent execution of sensitive actions on the device and in the connected house. The exploited vector was not a malicious app installed by the user, but Gemini's ability to read and act on the text of the notifications that reach him through the Utilities function.

The technique, baptized by the author as Fake Context Alignment, combined two misgivings: on the one hand, to inject a legible authorization question by the internal mechanisms of the assistant but hidden or expressed in a language that the user does not understand; on the other, to show the user an indefensible interaction and in his language that allows him to respond positively. This response, analyzed by the internal classifiers, ended up authorizing actions such as opening connected windows, starting apps or even forcing the union to remote meetings.

A single malicious notification could get Gemini to control your phone and home.
Image generated with IA.

More worrying was the demonstration of persistence: the researcher could induce Gemini to store a false memory in the account memory - for example, to change the victim's name - and to schedule recurrent tasks to extract information regularly. That is, the attack was not confined to the compromised phone, but to the user's Google profile. and could therefore accompany it on other devices using the same account.

The practical scope was extended by the ability of the notifications to contain clean links and readdresses that later led to domains or schemes that the wizard still did not reapply for, allowing IP geolocation, downloads or the automatic opening of other applications. SafeBreach indicates that there is no evidence of exploitation in real environments and that Google corrected the problem on the server after reporting vulnerability, but public design implications deserve attention.

From the point of view of security and privacy, the central lesson is that the text of the notifications is an input vector for attendees with reading and action capabilities. Designs that treat external information as "useful context" without a robust filtering are susceptible to indirect injections that the end user does not perceive. This is especially critical in mobility (driving) scenarios or when the interaction is purely auditory.

For users and administrators there are immediate practical measures: disconnect Gemini's Utilities function or revoke the reading and reporting permission for Google's Android app drastically reduces the attack surface. It is also appropriate to review and clean the "memory" of the assistant and the programmed tasks linked to the account, activate 2FA in the Google account and minimize the inclusion of sensitive data in messaging notifications that can be sent or replicated.

A single malicious notification could get Gemini to control your phone and home.
Image generated with IA.

In corporate environments, this type of abuse of notifications highlights the need for policies on the use of assistants in devices with access to sensitive data or physical control systems. Block automatic readdresses, limit notification permits and segment work and personal accounts are risk-reducing measures.

Google treated vulnerability as a priority and applied server side mitigation; as a result there is no app update that the user has to install, but the user's own configuration remains the most immediate defense. If you want to review and disable permissions and notification control in your account, check Google's tools to control activity and application permissions in your profile: Manage Google controls and activity. For more context on the original research and work of the team that discovered the problem, visit the SafeBreach main page: SafeBreach. It is also recommended to know how Google manages the disclosure of vulnerabilities through its reward program: Google Vulnerability Rewards Program.

In short, although the problem was already patched, the exposure showing these concept tests is a call of attention: attendees increasingly enter the human decision surface and require more rigid security and privacy controls. As long as manufacturers tighten their classifiers and authorisation flows, it is wise to audit permissions, segregate accounts and reduce the sensitive information you travel in notifications that any service can cause.

Coverage

Related

More news on the same subject.