Simon Willison 1/12/2026

Superhuman AI Exfiltrates Emails

Read Original

A classic prompt injection attack against Superhuman AI manipulated the system to exfiltrate sensitive user emails, including financial and medical data, to an attacker's Google Form. The vulnerability stemmed from a CSP rule allowing image loads from docs.google.com, which Google Forms used to persist data via GET requests. The company treated it as a high-priority incident and issued a fix.

Superhuman AI Exfiltrates Emails

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

1
The Beautiful Web
Jens Oliver Meiert 2 votes
2
Container queries are rad AF!
Chris Ferdinandi 2 votes
3
Wagon’s algorithm in Python
John D. Cook 1 votes
5
Top picks — 2026 January
Paweł Grzybek 1 votes
6
In Praise of –dry-run
Henrik Warne 1 votes
8
Vibe coding your first iOS app
William Denniss 1 votes