Custom Font Attack Exploits AI Assistants' Blind Spot

Custom Font Attack Exploits AI Assistants' Blind Spot

First seen 17 Mar 2026, 17:42 UTC BleepingcomputerCybersecuritynewsScworld 64.5

Article Content

Browse articles
ThreatCluster

A new attack technique has been discovered that targets AI web assistants by exploiting the gap between what browsers render and what AI tools read from HTML. Researchers at LayerX demonstrated that custom fonts and CSS can be used to hide malicious commands within seemingly harmless text, effectively tricking AI assistants like ChatGPT, Claude, and Gemini into providing false assurances about the safety of executing these commands. The attack relies on social engineering, where users are lured into executing harmful instructions displayed on a webpage. LayerX reported the vulnerability to affected AI vendors in December 2025, with Microsoft acknowledging the issue and addressing it, while Google later downgraded the severity. The technique has been successful against multiple AI assistants, raising significant concerns about the reliability of AI in assessing webpage safety. The attack method remains a critical security concern as it exploits a fundamental flaw in AI assistant design.

Key Points: • Custom font rendering can hide malicious commands from AI assistants. • LayerX's proof-of-concept successfully deceived multiple popular AI tools. • Microsoft addressed the vulnerability, while Google downgraded its severity.

Timeline

2025-12-16
LayerX reported findings to AI assistant vendors.
2025-12-16
Microsoft acknowledged and addressed the vulnerability.
2025-12-16
Google downgraded and closed the issue.
2026-03-17
Bleepingcomputer and Cybersecuritynews published articles.