Fact◆Article
The attack succeeded in extracting the user's name, home city, and employer name.
The exploit worked in practice, allowing exfiltration of the user's name, home location city, and employer. ✦ AI generated
Simon Willison · Simon Willison's Weblog · 2026-07-15 · original ↗
This worked! They were able to extract the user's name, home location city and the name of their employer.
Read full article ↗excerpt · fair-use quotation
- ·Attack extracted user's real name
- ·Revealed user's home location city
- ·Exposed name of user's employer
- ·Personal identity: full name
- ·Location data: home city
- ·Employment data: employer name
Around this claim
This moment responds to
gives example → The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.Article author · Simon Willison's Webloggives example → While hidden white-on-white text is a known technique, this attack is the first to deliberately copy instructions into outputs to achieve self-replication.Article author · Simon Willison's Weblogrebuts → Anthropic's web_fetch tool defends against exfiltration by only allowing navigation to exact URLs the user typed or that came back from web_search.Simon Willison · Simon Willison's Weblog