Skip to content
Custom Font Attack Exploits AI Assistants' Blind Spot

Custom Font Attack Exploits AI Assistants' Blind Spot

First seen 17 Mar 2026, 17:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 19, 2026 at 01:55 UTC
  • •Custom font rendering can hide malicious commands from AI assistants.
  • •LayerX's proof-of-concept successfully deceived multiple popular AI tools.
  • •Microsoft addressed the vulnerability, while Google downgraded its severity.

A new attack technique has been discovered that targets AI web assistants by exploiting the gap between what browsers render and what AI tools read from HTML. Researchers at LayerX demonstrated that custom fonts and CSS can be used to hide malicious commands within seemingly harmless text, effectively tricking AI assistants like ChatGPT, Claude, and Gemini into providing false assurances about the safety of executing these commands. The attack relies on social engineering, where users are lured into executing harmful instructions displayed on a webpage. LayerX reported the vulnerability to affected AI vendors in December 2025, with Microsoft acknowledging the issue and addressing it, while Google later downgraded the severity. The technique has been successful against multiple AI assistants, raising significant concerns about the reliability of AI in assessing webpage safety. The attack method remains a critical security concern as it exploits a fundamental flaw in AI assistant design.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2025-12-16
LayerX reported findings to AI assistant vendors.
2025-12-16
Microsoft acknowledged and addressed the vulnerability.
2025-12-16
Google downgraded and closed the issue.
2026-03-17
Bleepingcomputer and Cybersecuritynews published articles.

More articles in this cluster (3)