AI threats in the wild: The current state of prompt injections on the web

2026-05-05T13:23:50Zad75ea2aa0b8f6437b4687a755b841ac63d7284f59a5dad08efcd19b8a878ff9
DBSCIPILLM-securityPQCVRPandroidbasebandbrowser-securitycellular-modemcertificate-transparencychromecookie-theftdevice-bound-session-credentialsgenerative-ai-securitygoogle-workspaceindirect-prompt-injectioninfostealermemory-safetymerkle-tree-certificatespixelpost-quantum-cryptographyprompt-injectionquantum-safe-httpsrustvulnerability-rewards-program

What happened

A collection of Google Security Blog posts covering multiple high-impact security topics: monitoring and mitigation of Indirect Prompt Injection (IPI) attacks against LLM-based services and Google Workspace (including ongoing defenses and telemetry sweeps); rollout of Device Bound Session Credentials (DBSC) to prevent cookie theft (Windows in Chrome 146, macOS forthcoming); integration of a memory-safe Rust DNS parser into Pixel baseband firmware to reduce modem memory-safety bugs; Google VRP 2025 highlights; Android’s phased adoption of Post-Quantum Cryptography (PQC) starting with Android 17

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
ad75ea2aa0b8f6437b4687a755b841ac63d7284f59a5dad08efcd19b8a878ff9
Enrichment time
2026-05-05T13:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.