AI threats in the wild: The current state of prompt injections on the web

2026-06-27T07:23:41Zc97100934608f680a2d8a70ab3d2c2434a2d7c9bcd566e203bbdf476fb547d96
AI securityAndroid 17Certificate TransparencyDBSCDNS parserGeminiGoogle WorkspaceIPILLMMerkle Tree CertificatesPQCPixel basebandRustVRPVulnerability Rewards Programcookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsupply-chain security

What happened

A set of Google Security Blog posts covering multiple proactive security initiatives: (1) research and monitoring of Indirect Prompt Injection (IPI) and ongoing hardening of Google Workspace and Gemini against LLM prompt-injection threats; (2) Pixel baseband safety improvements by integrating a memory-safe Rust DNS parser to reduce modem memory-safety vulnerabilities; (3) rollout of Device Bound Session Credentials (DBSC) in Chrome to prevent cookie/session theft by malware; (4) a VRP (Vulnerability Rewards Program) 2025 year-in-review; and (5) efforts to prepare for the quantum era — Android

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
c97100934608f680a2d8a70ab3d2c2434a2d7c9bcd566e203bbdf476fb547d96
Enrichment time
2026-06-27T07:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI threats in the wild: The current state of prompt injections on the web · Baitaphish