AI threats in the wild: The current state of prompt injections on the web
2026-05-05T13:23:50Z•ad75ea2aa0b8f6437b4687a755b841ac63d7284f59a5dad08efcd19b8a878ff9
DBSCIPILLM-securityPQCVRPandroidbasebandbrowser-securitycellular-modemcertificate-transparencychromecookie-theftdevice-bound-session-credentialsgenerative-ai-securitygoogle-workspaceindirect-prompt-injectioninfostealermemory-safetymerkle-tree-certificatespixelpost-quantum-cryptographyprompt-injectionquantum-safe-httpsrustvulnerability-rewards-program
What happened
A collection of Google Security Blog posts covering multiple high-impact security topics: monitoring and mitigation of Indirect Prompt Injection (IPI) attacks against LLM-based services and Google Workspace (including ongoing defenses and telemetry sweeps); rollout of Device Bound Session Credentials (DBSC) to prevent cookie theft (Windows in Chrome 146, macOS forthcoming); integration of a memory-safe Rust DNS parser into Pixel baseband firmware to reduce modem memory-safety bugs; Google VRP 2025 highlights; Android’s phased adoption of Post-Quantum Cryptography (PQC) starting with Android 17
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- ad75ea2aa0b8f6437b4687a755b841ac63d7284f59a5dad08efcd19b8a878ff9
- Enrichment time
- 2026-05-05T13:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.