Mark RadarMARK RADAR
EN

‘Poisoned Typeface’ Attack Uses Custom Fonts to Trick AI Assistants Into Executing Malicious Instructions

2 reports · First detected 2026-03-18 · Last active 2026-03-18

Cybersecurity company LayerX has uncovered a “Poisoned Typeface” attack in which hackers use custom fonts and CSS to make the content displayed in a browser differ from the underlying HTML. Because AI assistants such as OpenAI’s ChatGPT and Google’s Gemini may interpret information based on a webpage’s structure, attackers can use the technique to bypass content checks, exposing security gaps in AI web parsing and agentic operations.

A March 18 cybersecurity report said the font-rendering attack could lead AI assistants to misclassify a webpage as harmless even though the text shown to users may prompt them to download malware or execute commands. LayerX testing found that the vulnerability stems from differences between the text read by AI systems and the browser’s final rendered output. No victim losses or large-scale attack cases have been disclosed.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR