Skip to main navigation Skip to search Skip to main content

URLcoat: Exploiting Web Search Capability to Jailbreak Large Language Models

  • Yiheng Sun
  • , Linkang Du
  • , Zhou Su
  • , Yuntao Wang
  • , Han Liu
  • Xi'an Jiaotong University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Large language models (LLMs) achieve remarkable advances in understanding and reasoning with human language, which are widely applied in software development, content creation, healthcare, etc. However, their vulnerabilities to security threats, especially jailbreak attacks, remain a significant issue. Existing research on jailbreak mainly focuses on the security risks of LLMs' inherent thinking and reasoning, overlooking the new attack surface introduced by web search capability. Attackers can exploit this by guiding LLMs to retrieve information from external URLs, which is then used to implicitly reconstruct harmful instructions and circumvent safety mechanisms, leading to the generation of harmful content. In this paper, we propose a novel jailbreak attack, named URLcoat. The core idea is to exploit the web search capabilities of LLMs to circumvent their security safeguards. URLcoat incorporates three core strategies: obfuscating the feature of sensitive words to evade input detection, reconstructing harmful instructions via implicit associations with external URLs, and contextual narrative guidance to bypass output filtering. The experimental results reveal that URLcoat attains 100 % attack success rates in mainstream LLMs, including GPT5, GPT-4o, Gemini 2.0 Flash Thinking, DeepSeek R1, Kimi 1.5, ChatGLM-4, Grok 3, Gemini 2.5 Pro, Gemini 2.5 Flash, and Gemini 2.0 Flash, exceeding the performance of state-of-the-art jailbreak techniques. This study examines the security vulnerabilities arising from lLMs' web search capability, which facilitates the LLMs to produce harmful output.

Original languageEnglish
Title of host publicationProceedings - 47th IEEE Symposium on Security and Privacy, SP 2026
EditorsAlina Oprea, Cristina Nita-Rotaru, Nicolas Papernot
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages59-77
Number of pages19
ISBN (Electronic)9798331560652
DOIs
StatePublished - 2026
Event47th IEEE Symposium on Security and Privacy, SP 2026 - San Francisco, United States
Duration: 18 May 202621 May 2026

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
ISSN (Print)1081-6011

Conference

Conference47th IEEE Symposium on Security and Privacy, SP 2026
Country/TerritoryUnited States
CitySan Francisco
Period18/05/2621/05/26

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 3 - Good Health and Well-being
    SDG 3 Good Health and Well-being

Fingerprint

Dive into the research topics of 'URLcoat: Exploiting Web Search Capability to Jailbreak Large Language Models'. Together they form a unique fingerprint.

Cite this