AI threats in the wild: The current state of prompt injections on the web

2026-05-18T13:23:37Z5d67fe59e7d308958b62ff34fb6d900b2bd19057ef4f31127483be1edc4e8c56
AI safetyAndroidAndroid 17DBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceIPILLM securityMerkle Tree CertificatesPLANTS (IETF)PQCPixel basebandRustVRPVulnerability Rewards Programcookie theftindirect prompt injectioninfostealermemory safetymodem firmwarepost-quantum cryptographyquantum-safe HTTPSsession hijacking

What happened

This collection of Google Security Blog posts covers several high-impact security initiatives and emerging threats. Key items: (1) Indirect Prompt Injection (IPI) is prioritized as an active and evolving threat against LLM-based agents (e.g., Workspace/Gemini); Google ran broad web sweeps and describes continuous mitigations and hardening of AI apps. (2) Device Bound Session Credentials (DBSC) are entering public availability on Chrome (Windows; macOS coming) to prevent stolen/exfiltrated cookies from being reused by attackers (mitigates infostealer-based session theft). (3) Pixel baseband/mit

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
5d67fe59e7d308958b62ff34fb6d900b2bd19057ef4f31127483be1edc4e8c56
Enrichment time
2026-05-18T13:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.