A new theoretical attack described by researchers with LayerX lays out how frighteningly simple it would be for a malicious or compromised browser extension to intercept user chats with LLMs and insert prompt injection attacks designed to exfiltrate data without the target being aware.
Called the "Policy Puppetry Attack," the new prompt injection attack focuses on formatting requests to look like the contents of one of the policy files that AI models rely on for their security and safety guidelines.
A new report from cybersecurity firm HiddenLayer finds that Google Gemini is vulnerable to prompt injection attacks. The researchers characterize it as being open to "profound misuse."



