The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have disclosed a new class of AI vulnerability called Agent Data Injection (ADI), where attackers corrupt trusted data like sender names, button IDs, or tool records so AI agents act on planted information instead of hijacking the task itself.
- In tests, this made web agents click 'Buy Now' instead of 'Read More', let fake GitHub comments run commands on developers' machines, and let malicious pull requests pass fake safety checks.
- Every major model tested — OpenAI's GPT-5.2 and GPT-5-mini, Anthropic's Claude Opus 4.5 and Sonnet 4.5, and Google's Gemini 3 Pro and Flash — proved vulnerable, and existing defenses built against classic prompt injection largely failed to stop it.
- The researchers reported the findings to vendors before publishing, and there is no public report of ADI being used in the wild yet.
What to watch next
- Vendor responses and patches from OpenAI, Google, and Anthropic; Nanobrowser had not replied as of the paper
- Adoption of defenses like random element IDs and data-tracking, which reduced or eliminated attacks in testing
- Any first real-world reports of ADI being exploited, since only proof-of-concept attacks exist so far
Coverage1
All filed from India
Named United States · South Korea · Anthropic · Claude Code · Claude Opus 4.5 · Claude Sonnet 4.5 · Gemini 3 Pro · Gemini Flash · Google · GPT-5.2 · GPT-5-mini · OpenAI · Byoungyoung Lee · Largosoft
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
