‘Poisoned Typeface’ Attack Uses Custom Fonts to Trick AI Assistants Into Executing Malicious Instructions
Cybersecurity company LayerX has uncovered a “Poisoned Typeface” attack in which hackers use custom fonts and CSS to make the content displayed in a browser differ from the underlying HTML. Because AI assistants such as OpenAI’s ChatGPT and Google’s Gemini may interpret information based on a webpage’s structure, attackers can use the technique to bypass content checks, exposing security gaps in AI web parsing and agentic operations.
A March 18 cybersecurity report said the font-rendering attack could lead AI assistants to misclassify a webpage as harmless even though the text shown to users may prompt them to download malware or execute commands. LayerX testing found that the vulnerability stems from differences between the text read by AI systems and the browser’s final rendered output. No victim losses or large-scale attack cases have been disclosed.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.