Visual Spoofing Attack Uses CSS and Font Mapping to Trick AI into Endorsing Malicious Code

xiaohu · x · 2026-07-30

Cybersecurity firm LayerX has uncovered a novel 'visual spoofing' attack targeting AI assistants, affecting nearly all major AI tools.

The exploit leverages the discrepancy between human visual perception and how AI parses underlying HTML (DOM structure):

Result: The AI reads the harmless underlying code and evaluates it as 'safe,' while the user sees the rendered malicious command. If the user trusts the AI's assessment and executes the code, their device is compromised.

Original post →

More from Safety

Safety channel →