AI threats in the wild: The current state of prompt injections on the web

2026-05-04T13:23:46Zade32505443038513a2275c5638ce97ceaa45a29a794e57858df3ea86f257af6
AI securityAndroid 17Certificate TransparencyDBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceLLM securityLummaC2Merkle Tree CertificatesPLANTSPQCPixel basebandRustVRPVulnerability Rewards Programcookie theftindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyprompt injectionquantum-safe HTTPS

What happened

A Google Security Blog roundup covering multiple product- and industry-level defenses: research and real-world monitoring show Indirect Prompt Injection (IPI) is an active and prioritized threat to AI/LLM-based systems, and Google is continuously hardening Workspace/Gemini against IPI. Chrome is rolling out Device Bound Session Credentials (DBSC) to proactively prevent cookie/session theft from infostealer malware. Pixel firmware work replaces unsafe modem DNS parsing with a Rust implementation to reduce memory-safety vulnerabilities. Google published its VRP 2025 review, and announced Android

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
ade32505443038513a2275c5638ce97ceaa45a29a794e57858df3ea86f257af6
Enrichment time
2026-05-04T13:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI threats in the wild: The current state of prompt injections on the web · Baitaphish