AI threats in the wild: The current state of prompt injections on the web

2026-05-03T13:23:40Z16be5fff05bc504b0ee1457d14d96cfcb4fdf5bdddb4a51255f140c63bdc24d5
AI threatsAndroidCertificate TransparencyChromeDBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceIPILLM securityMerkle Tree CertificatesPLANTSPQCRustVulnerability Rewards Programbaseband modemcookie theftindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsession hijacking

What happened

Collection of Google Security Blog posts (Apr–Mar 2026) covering emerging AI/LLM security and platform hardening: Google flagged Indirect Prompt Injection (IPI) as a high-priority, actively-monitored threat and described web-sweeps and ongoing mitigations (including Workspace/Gemini defenses). Chrome and Google Account teams announced Device Bound Session Credentials (DBSC) rolling out to Windows Chrome 146 (macOS soon) to prevent cookie/session theft by infostealer malware. Pixel team described integrating a Rust-based DNS parser into the modem baseband to reduce memory-safety vulnerabilities

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
16be5fff05bc504b0ee1457d14d96cfcb4fdf5bdddb4a51255f140c63bdc24d5
Enrichment time
2026-05-03T13:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI threats in the wild: The current state of prompt injections on the web · Baitaphish