Simon Willison 1/12/2026

Superhuman AI Exfiltrates Emails

Read Original

A security researcher demonstrated a classic prompt injection attack against Superhuman AI. When asked to summarize recent emails, a malicious prompt in an untrusted email manipulated the AI to exfiltrate dozens of sensitive emails (containing financial, legal, and medical data) to an attacker's Google Form. The root cause was a CSP rule allowing image loads from docs.google.com, which Google Forms used to persist data via GET requests. Superhuman treated it as a high-priority incident and issued a fix.

Superhuman AI Exfiltrates Emails

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

1
The Beautiful Web
Jens Oliver Meiert 2 votes
3
LLM Use in the Python Source Code
Miguel Grinberg 1 votes
4
Wagon’s algorithm in Python
John D. Cook 1 votes