AI + Mobile (LLM x IPC / WebView)

The emerging crossover surface where an on-device AI assistant meets classic mobile trust boundaries: untrusted mobile input (deep links, clipboard, QR, notifications, WebView content) flowing INTO an LLM prompt, and LLM OUTPUT flowing back OUT into a WebView, an Intent/URL, or a tool/command invocation - without a validation boundary in between. Signalled by real 2025-2026 disclosures such as Microsoft 365 Copilot for iOS/Android (CVE-2026-26133, command injection) and Monica ChatGPT Assistant (CVE-2024-48142, prompt-injection data exfiltration).

5 vulnerabilities. OWASP Mobile: M4