
A new type of attack exploits how fonts are rendered to trick AI helpers into overlooking harmful commands embedded in web pages, using seemingly harmless code.
The method relies on tricking users into executing a harmful command displayed on a web page. This command is encoded in the HTML, preventing AI assistants from detecting it.
Researchers at LayerX, a company specializing in browser security, created a demonstration showing how custom fonts can be used to change characters through glyph substitution. They also used CSS styles to hide the safe text by making the font very small or using a specific color, while clearly displaying the malicious command on the page.
In testing, the AI tools examined the HTML code and only saw the safe text added by the attacker. They didn’t check the harmful information presented to the user in the browser.
To conceal the dangerous command, the researchers transformed it into seemingly random and unreadable characters for the AI assistant. However, the browser translates this jumble of characters and displays the malicious instruction on the page.
LayerX reports that, as of December 2025, this method successfully bypassed the defenses of several well-known AI assistants, like ChatGPT, Claude, Copilot, Gemini, Leo, Grok, Perplexity, Sigma, Dia, Fellou, and Genspark.
“AI assistants analyze web pages as structured text, while browsers convert that text into a visual representation for the user,” the researchers stated.
“Attackers can manipulate how a page appears to humans without making changes to the underlying code. This happens within the browser’s rendering process.
“This difference between what the AI assistant sees and what the user sees leads to incorrect responses, risky suggestions, and a decrease in trust,” LayerX explains in a report released today.
The attack starts when a user visits a website that seems safe and promises a reward if they run a command on their computer to create a reverse shell. If the user asks an AI assistant if the command is safe, they will receive a reassuring answer.
To illustrate the attack, LayerX developed a demonstration page that offers an easter egg for the Bioshock video game if the user follows the on-screen directions.
The page’s HTML includes safe text that is hidden from the user but visible to the AI assistant, along with the dangerous command that the AI ignores because it’s encoded, but appears to the user through a special font.
As a result, the AI assistant only understands the safe portion of the page and cannot provide an accurate response when asked about the safety of the command.
LayerX informed the makers of the affected AI assistants about their findings on December 16, 2025. However, most considered it “out of scope” because it requires tricking the user.
Microsoft was the only company that acknowledged the report and asked for a date to publicly disclose the issue, escalating the report by opening a case in MSRC. LayerX states that Microsoft “fully addressed” the problem.
Google initially accepted the report, marking it as high priority, but later lowered its importance and closed the issue, arguing that it wouldn’t cause “significant user harm” and relied too much on tricking the user.
The general advice for users is to not completely rely on AI assistants, as they might not have defenses against certain kinds of attacks.
LayerX suggests that an LLM that analyzes both the displayed page and the text-only code, and then compares them, would be better at assessing the safety for the user.
The researchers further advise LLM providers to treat fonts as a potential attack point, and to improve parsers to look for matching foreground and background colors, near-zero opacity, and fonts that are too small.
#actors #allows #artificial #bad #clever #conceal #font-rendering #from #harmful #instructions #intelligence #news #systems #technique — News
© Bulletproof Servers. All rights reserved.