AI threats in the wild: The current state of prompt injections on the web
2026-05-07T19:23:46Z•8480a21f6015910e5595611060c5013cbbeda022519eb1212a65f43f80be1710
AI threatsAndroid 17Chrome 146DBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2MTCsMerkle Tree CertificatesPQCPixel basebandRustcookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetymodem firmwarepost-quantum cryptographyprompt injectionquantum-safe HTTPSsession theft
What happened
This collection of Google Security Blog posts highlights multiple active and near-term security priorities: indirect prompt injection (IPI) and other AI-targeted attacks (Google performed a web-wide sweep for IPI patterns and describes ongoing Workspace / Gemini mitigations); protections against session-theft via Device Bound Session Credentials (DBSC) rolling out to Chrome on Windows (and soon macOS) to stop cookie replay by infostealer malware; strengthening Pixel baseband memory safety by integrating a Rust DNS parser to reduce exploitation risk in modem firmware; continued investment in PQ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 8480a21f6015910e5595611060c5013cbbeda022519eb1212a65f43f80be1710
- Enrichment time
- 2026-05-07T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.