AI threats in the wild: The current state of prompt injections on the web
2026-05-03T13:23:40Z•16be5fff05bc504b0ee1457d14d96cfcb4fdf5bdddb4a51255f140c63bdc24d5
AI threatsAndroidCertificate TransparencyChromeDBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceIPILLM securityMerkle Tree CertificatesPLANTSPQCRustVulnerability Rewards Programbaseband modemcookie theftindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsession hijacking
What happened
Collection of Google Security Blog posts (Apr–Mar 2026) covering emerging AI/LLM security and platform hardening: Google flagged Indirect Prompt Injection (IPI) as a high-priority, actively-monitored threat and described web-sweeps and ongoing mitigations (including Workspace/Gemini defenses). Chrome and Google Account teams announced Device Bound Session Credentials (DBSC) rolling out to Windows Chrome 146 (macOS soon) to prevent cookie/session theft by infostealer malware. Pixel team described integrating a Rust-based DNS parser into the modem baseband to reduce memory-safety vulnerabilities
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 16be5fff05bc504b0ee1457d14d96cfcb4fdf5bdddb4a51255f140c63bdc24d5
- Enrichment time
- 2026-05-03T13:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.