AI threats in the wild: The current state of prompt injections on the web

2026-05-19T13:23:39Zb68f0539c907fbca36ca8f1a3068da466d445e3b282c124ce17dfb36d936352a
AndroidAndroid 17DBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceIPILLM securityLummaC2MTCs","Certificate Transparency","ChromeMerkle Tree CertificatesPQCPixel basebandRustVRPVulnerability Rewards Programcookie theftindirect prompt injectioninfostealermemory-safetymodem securitypost-quantum cryptographyprompt-injectionquantum-safe HTTPS

What happened

A set of Google Security Blog posts covering multiple active security topics: (1) analysis and real-world monitoring of indirect prompt injection (IPI) attacks against LLM-based agents and continuous mitigations (including Google Workspace/Gemini defenses); (2) adoption of Rust for a memory‑safe DNS parser in the Pixel modem/baseband to reduce memory-safety vulnerabilities; (3) public availability rollout of Device Bound Session Credentials (DBSC) in Chrome to prevent cookie/session exfiltration and abuse by infostealer malware (e.g., LummaC2); (4) the Vulnerability Rewards Program (VRP) 2025年

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
b68f0539c907fbca36ca8f1a3068da466d445e3b282c124ce17dfb36d936352a
Enrichment time
2026-05-19T13:23:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.