Cybersecuritynews Custom Font Attack Exploits AI Assistants' Blind Spot
Article Content
- •Custom font rendering can hide malicious commands from AI assistants.
- •LayerX's proof-of-concept successfully deceived multiple popular AI tools.
- •Microsoft addressed the vulnerability, while Google downgraded its severity.
A new attack technique has been discovered that targets AI web assistants by exploiting the gap between what browsers render and what AI tools read from HTML. Researchers at LayerX demonstrated that custom fonts and CSS can be used to hide malicious commands within seemingly harmless text, effectively tricking AI assistants like ChatGPT, Claude, and Gemini into providing false assurances about the safety of executing these commands. The attack relies on social engineering, where users are lured into executing harmful instructions displayed on a webpage. LayerX reported the vulnerability to affected AI vendors in December 2025, with Microsoft acknowledging the issue and addressing it, while Google later downgraded the severity. The technique has been successful against multiple AI assistants, raising significant concerns about the reliability of AI in assessing webpage safety. The attack method remains a critical security concern as it exploits a fundamental flaw in AI assistant design.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…