AI threats in the wild: The current state of prompt injections on the web
2026-07-23T13:23:41Z•4149df230f3ae9392a1e245988c404b517d4561423a213e6fae316508071f903
ai-securityandroid-17certificate-transparencychromecookie-theftdbscdevice-bound-session-credentialsdns-parsergeminiindirect-prompt-injectioninfostealerlummac2memory-safetymerkle-tree-certificatesmodem-securitypixel-basebandplants-working-grouppost-quantum-cryptographypqcprompt-injectionquantum-safe-httpsrustvrpvulnerability-reward-programworkspace
What happened
This collection of Google Security Blog posts covers several active and emerging security initiatives and threats. Google Threat Intelligence highlights indirect prompt injection (IPI) as a top AI attack vector, reports a web sweep for real-world IPI patterns, and describes continuous mitigations for Workspace/Gemini to reduce IPI risk. Chrome and Google Account teams announced Device Bound Session Credentials (DBSC) entering public availability on Windows (Chrome 146) with macOS support forthcoming; DBSC proactively prevents session-cookie replay by tying session tokens to a device to defeat‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 4149df230f3ae9392a1e245988c404b517d4561423a213e6fae316508071f903
- Enrichment time
- 2026-07-23T13:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.