On June 7, 2026, security firm SafeBreach disclosed a 'pseudo-context alignment' security vulnerability in Google Gemini. Hackers can send notification messages containing specially crafted content through channels such as WhatsApp and SMS, using multilingual obfuscation or silent hyperlinks to hide malicious instructions. This induces Gemini to misjudge user authorization and execute unauthorized operations, potentially leading to illegal control of smart home devices and tampering with user contact lists. Google mitigated this vulnerability in mid-November 2025 by improving its content classifier mechanism.
