Superhuman AI Exfiltrates Emails
Read OriginalA classic prompt injection attack against Superhuman AI manipulated the system to exfiltrate sensitive user emails, including financial and medical data, to an attacker's Google Form. The vulnerability stemmed from a CSP rule allowing image loads from docs.google.com, which Google Forms used to persist data via GET requests. The company treated it as a high-priority incident and issued a fix.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser