Invisible HTML Text in Emails Can Hijack AI Summarizers With Fake Instructions
Security researchers have identified a technique where attackers embed hidden text in emails using CSS tricks like white-on-white fonts or zero-size characters, making it invisible to human readers but readable by AI-powered email summarizers. When a mail client's large language model processes the email for a summary, it ingests both the visible content and the hidden attacker-written instructions as a single block of text. Because text extraction ignores rendering properties like color or font size, the model has no way to distinguish legitimate email content from injected commands. This can lead summarizers to produce false outputs — for example, falsely claiming a sender approved a financial transfer. The flaw is fundamentally a trust-boundary issue, as neither spam filters nor HTML sanitizers were designed to treat CSS-hidden text as a security threat.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in