0
Applied AI·June 4, 2026·1 min read

Hackers could use poisoned WhatsApp and Slack notifications to take over your Google Gemini – and make it work on their behalf

Share

Prompt injection via Android notifications shows the attack surface is now every UX surface where text touches an assistant—not just the chat window. If you’re shipping agentic workflows, you need a red-team pass on notification channels and third-party integrations this week, or you’re delegating control to whoever can send a message.