Superhuman AI Exfiltrates Emails
Read OriginalA classic prompt injection attack against Superhuman AI manipulated the system to exfiltrate sensitive user emails, including financial and medical data, to an attacker's Google Form. The vulnerability stemmed from a CSP rule allowing image loads from docs.google.com, which Google Forms used to persist data via GET requests. The company treated it as a high-priority incident and issued a fix.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
1
React vs Browser APIs (Mental Model)
Jivbcoop
•
3 votes
2
3
Building Type-Safe Compound Components
TkDodo Dominik Dorfmeister
•
2 votes
4
Introducing RSC Explorer
Dan Abramov
•
1 votes
5
The Pulse: Cloudflare’s latest outage proves dangers of global configuration changes (again)
The Pragmatic Engineer Gergely Orosz
•
1 votes