Simon Willison 1/12/2026

Superhuman AI Exfiltrates Emails

Read Original

A security researcher demonstrated a classic prompt injection attack against Superhuman AI. When asked to summarize recent emails, a malicious prompt in an untrusted email manipulated the AI to exfiltrate dozens of sensitive emails (containing financial, legal, and medical data) to an attacker's Google Form. The root cause was a CSP rule allowing image loads from docs.google.com, which Google Forms used to persist data via GET requests. Superhuman treated it as a high-priority incident and issued a fix.

Superhuman AI Exfiltrates Emails

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet