logo

Custom Fonts Can Trick AI Assistants Into Approving Phishing Sites

ID: 0519de31-1da1-5b35-b578-39b1e195c9bc

STIX ID: report--0519de31-1da1-5b35-b578-39b1e195c9bc

Feed Name: KnowBe4 Blog

Threat Score
50/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

LayerX researchers demonstrated a technique where custom fonts and CSS cause a mismatch between a page's rendered content and its underlying HTML/DOM, allowing attackers to hide malicious instructions from AI web assistants while showing different content to human users; their proof-of-concept phishing page (leading to a reverse shell) fooled multiple major AI assistants, and most vendors considered the issue out of scope for model security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.