The images in this article were generated with artificial intelligence. How we publish
A SafeBreach researcher showed that, until Google's correction, a single malicious notification sent to an Android phone could manipulate the voice assistant Gemini and cause from false messages to the silent execution of sensitive actions on the device and in the connected house. The exploited vector was not a malicious app installed by the user, but Gemini's ability to read and act on the text of the notifications that reach him through the Utilities function.
The technique, baptized by the author as Fake Context Alignment, combined two misgivings: on the one hand, to inject a legible authorization question by the internal mechanisms of the assistant but hidden or expressed in a language that the user does not understand; on the other, to show the user an indefensible interaction and in his language that allows him to respond positively. This response, analyzed by the internal classifiers, ended up authorizing actions such as opening connected windows, starting apps or even forcing the union to remote meetings.

More worrying was the demonstration of persistence: the researcher could induce Gemini to store a false memory in the account memory - for example, to change the victim's name - and to schedule recurrent tasks to extract information regularly. That is, the attack was not confined to the compromised phone, but to the user's Google profile. and could therefore accompany it on other devices using the same account.
The practical scope was extended by the ability of the notifications to contain clean links and readdresses that later led to domains or schemes that the wizard still did not reapply for, allowing IP geolocation, downloads or the automatic opening of other applications. SafeBreach indicates that there is no evidence of exploitation in real environments and that Google corrected the problem on the server after reporting vulnerability, but public design implications deserve attention.
From the point of view of security and privacy, the central lesson is that the text of the notifications is an input vector for attendees with reading and action capabilities. Designs that treat external information as "useful context" without a robust filtering are susceptible to indirect injections that the end user does not perceive. This is especially critical in mobility (driving) scenarios or when the interaction is purely auditory.
For users and administrators there are immediate practical measures: disconnect Gemini's Utilities function or revoke the reading and reporting permission for Google's Android app drastically reduces the attack surface. It is also appropriate to review and clean the "memory" of the assistant and the programmed tasks linked to the account, activate 2FA in the Google account and minimize the inclusion of sensitive data in messaging notifications that can be sent or replicated.

In corporate environments, this type of abuse of notifications highlights the need for policies on the use of assistants in devices with access to sensitive data or physical control systems. Block automatic readdresses, limit notification permits and segment work and personal accounts are risk-reducing measures.
Google treated vulnerability as a priority and applied server side mitigation; as a result there is no app update that the user has to install, but the user's own configuration remains the most immediate defense. If you want to review and disable permissions and notification control in your account, check Google's tools to control activity and application permissions in your profile: Manage Google controls and activity. For more context on the original research and work of the team that discovered the problem, visit the SafeBreach main page: SafeBreach. It is also recommended to know how Google manages the disclosure of vulnerabilities through its reward program: Google Vulnerability Rewards Program.
In short, although the problem was already patched, the exposure showing these concept tests is a call of attention: attendees increasingly enter the human decision surface and require more rigid security and privacy controls. As long as manufacturers tighten their classifiers and authorisation flows, it is wise to audit permissions, segregate accounts and reduce the sensitive information you travel in notifications that any service can cause.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...