for you hax0rs: Google "AI" is currently vulnerable to prompt injection by "ASCII smuggling"—this is when you convert ASCII to Unicode tag characters, rendering them invisible to the user but visible to the LLM. here's how it's done:
gist.github.com/Shadow0ps/a7dc…
here's someone using this to make Google Calendar display spoofed information about a meeting:
firetail.ai/blog/ghosts-in-the…
others say summarising functions were affected too, so I wonder if you can add tag texts to your website and poison the Google so-called "AI summary" anti-feature.
ChatGPT filters out tag character but, usefully, Google is refusing to, so unless they get a backlash this might be a fun exploit to explore: pivot-to-ai.com/2025/10/11/goo…
Ghosts in the Machine: ASCII Smuggling across Various LLMs
Researcher Viktor Markopoulos discovers ASCII Smuggling bypasses human audit via Unicode, enabling enterprise identity spoofing and data poisoning on Gemini & Grok.Alan Fagan (FireTail)
Winter blue tardis
in reply to Erion • • •