Security researchers at SafeBreach disclosed a technique called “Fake Context Alignment,” in which crafted notifications from everyday apps like WhatsApp, Slack, and SMS could silently inject instructions into Google’s Gemini voice assistant on Android. The flaw let an attacker make Gemini open windows, fabricate messages appearing to be from real contacts, join calls, or poison the assistant’s long-term memory, all without the user’s awareness. The issue was privately reported to Google in August 2025, patched in November 2025, and publicly disclosed June 3, 2026, with no confirmed real-world exploitation reported.