AI threats in the wild: The current state of prompt injections on the web
2026-06-26T19:23:42Z•9d03766d8757be11f007f53d9c8f9baed83df5b13c15825961ef8430c010beea
Android 17Certificate TransparencyDBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2MTCMerkle Tree CertificatesPLANTSPQCPixel modemRustVRPbaseband securitycookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionvulnerability rewards program
What happened
Google Security posts (Apr 2026) cover active and emerging threats plus mitigations: indirect prompt injection (IPI) is a prioritized, real-world threat with Google reporting a web-wide sweep and ongoing defenses for Workspace/Gemini; Device Bound Session Credentials (DBSC) are being deployed in Chrome to proactively block session-cookie theft by infostealer malware; Pixel baseband security is being improved by adding a memory-safe Rust DNS parser to reduce memory-safety bugs; Android and Chrome are advancing post‑quantum cryptography (PQC) rollouts (Android 17 tests, Merkle Tree Certificates/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 9d03766d8757be11f007f53d9c8f9baed83df5b13c15825961ef8430c010beea
- Enrichment time
- 2026-06-26T19:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.