Prnewswire DeepKeep Reveals InkJect: New Visual Prompt Injection Vulnerability in AI Models
Article Content
- •InkJect vulnerability affects major VLMs, including OpenAI's GPT-5.2 and Claude Sonnet 4.6.
- •Malicious instructions can be embedded in images, bypassing existing security measures.
- •The vulnerability has received little academic attention, indicating a significant security gap.
DeepKeep has identified a new visual prompt injection vulnerability named 'InkJect' that affects leading visual language models (VLMs) like OpenAI's GPT-5.2 and Anthropic's Claude Sonnet 4.6. This vulnerability allows malicious actors to embed hidden instructions within images, which VLMs process without detection, leading to unauthorized actions. The attack exploits a gap in existing security measures that focus on text-based prompt injections, leaving visual processing layers vulnerable. As enterprises increasingly adopt multimodal AI solutions, the risk associated with this vulnerability is expected to grow. DeepKeep's research highlights that this attack vector has received minimal academic attention, with only one prior paper addressing it. The hidden instructions can evade detection through techniques like white text on white backgrounds and distorted text perspectives. In tests, the vulnerability enabled an attacker to insert a backdoor into a website without the developer's knowledge.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…