New font-rendering trick hides malicious commands from AI tools
ID: 353084ee-ee7c-54f9-af7c-bc9298d29135
STIX ID: report--353084ee-ee7c-54f9-af7c-bc9298d29135
Feed Name: Bleeping Computer
Threat Score
LayerX published a PoC showing a font-rendering attack that uses glyph substitution and CSS tricks to display malicious commands to users while the HTML DOM contains only benign text — causing AI assistants that inspect the DOM to miss the payload; the report documents tests against multiple popular assistants, vendor responses (Microsoft engaged, others largely downgraded), and recommendations to treat fonts and rendering discrepancies as an attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
