Your Voice Assistant Can Be Social-Engineered Too, and Nobody's Watching For It
We spent a decade teaching people not to click the phishing link. Now we've built agents that will happily take instructions from whatever's playing in the background, and we haven't even started teaching them not to. Prompt injection in text is old news at this point. Paste some hidden instructions into a document, a webpage, an email, and watch an LLM agent dutifully follow them instead of the user's actual request. We've had two-plus years of research, blog posts, and "here's why this is arch
