Scientists warn AI agents carry massive security flaws as browsers bypass core protections

3 Sources

Share

Researchers from the University of Washington have uncovered critical security flaws in popular AI web browsers that bypass fundamental internet safety protocols. The study examined seven AI agentic browsers including ChatGPT Atlas and Claude for Chrome, finding that the most powerful browsers create pathways for malicious websites to steal user data through prompt injection and memory poisoning attacks.

AI Web Browsers Bypass Fundamental Security Protocols

Researchers from the University of Washington have issued a stark warning about AI security vulnerabilities in popular AI agents and AI web browsers, declaring that these tools "aren't ready for the public." In a study presented at the Agents in the Wild Workshop in Rio de Janeiro on April 26, scientists examined seven AI agentic browsers and discovered that four create pathways for malicious actors to bypass the same-origin policy, a fundamental cybersecurity protocol introduced in 1995 that prevents websites from interacting with each other's information

1

2

.

Source: Futurity

Source: Futurity

The research team successfully executed a proof-of-concept cyberattack on ChatGPT Atlas, demonstrating how a malicious website embedded within another site could steal sensitive information, similar to an advertisement on an email platform snatching data from user emails. They also identified conditions for similar attacks in Chrome with Gemini, Claude for Chrome, and Perplexity Comet

2

. "Even if you're a relatively savvy user, if these agents have access to a browser that contains your credentials -- your email, your bank account, whatever it is -- you should not trust that these systems are ready to truly protect your information," said David Kohlbrenner, assistant professor of computer science and engineering at the University of Washington

1

.

Critical Security Flaws Through Prompt Injection and Memory Poisoning

The study identified multiple attack surfaces that expose user data to cybersecurity risks. Prompt injection emerged as a major vulnerability, where AI agents can be tricked into misinterpreting data embedded on a malicious website as instructions they need to execute. An example scenario involves an AI agent visiting a seemingly safe site containing hidden code that instructs the browser to automatically share personal details through an auto-submitting form

1

2

.

Memory poisoning represents another severe threat to AI agent security. AI agents store and consolidate information they've processed to guide future actions, making their memory contents vulnerable to data theft. "We found that some of these agents would mingle information from different origins, likely because they were revising and compressing their memory," explained Franziska Roesner, professor at the University of Washington

2

. This means a malicious instruction could persist in an agent's memory and execute later, even after initial safeguards prevented the immediate attack.

Browser Capabilities Directly Correlate With Security Risks

Source: Live Science

Source: Live Science

The research revealed a troubling pattern: the more capable the AI agentic browsers, the greater the security risks they pose. The team examined ChatGPT Atlas, Claude for Chrome, Brave Leo AI, Chrome with Gemini, Microsoft Edge with CoPilot, Firefox AI Mode, and Perplexity Comet, focusing on what information each agent could access from same-origin and cross-origin webpages, what actions they could undertake, and their chat context and history

1

.

The findings showed no consistency in how AI web browsers operate, likely due to lack of standardization in how they interact with browser security. Several browsers could freely access cross-origin frame content while others restricted access. Some could simultaneously access multiple tabs, but most required user permission. The researchers expressed particular caution about Anthropic's Claude for Chrome, known for its strong capabilities, as well as ChatGPT Atlas and Comet, which have similarly powerful functionality

1

.

Broader Attack Patterns Emerge Across AI Agent Ecosystem

The browser vulnerabilities represent just one facet of a larger AI security crisis. In July, four separate research teams identified critical security flaws across different AI agent implementations within roughly ten days. Security firm Manifold Security demonstrated that browser extensions could hijack Claude for Chrome and access Gmail, Google Docs, and Calendar by forging user clicks in just six lines of code. The firm reported the vulnerability to Anthropic in May, but eight releases later, the flaw remained exploitable

3

.

Another study posted to arXiv showed that a single carefully crafted email could plant false memories in AI agents connected to Gmail. The poisoned memory persisted across future sessions, steering the agent's behavior without alerting the user. Meanwhile, researcher Katie Paxton-Fear at Semgrep demonstrated model poisoning for under £75, showing that just ten tainted training examples could make a model write code with hidden security holes

3

.

PromptArmor's research on connectors linking ChatGPT and Claude to services like Gmail and Slack revealed a rapidly evolving threat landscape. Of 2,517 connectors tracked, 931 changed within six weeks, with connectors shifting on average every nine minutes. The Dropbox connector alone grew from eight tools to 24, with four now capable of destroying data. When users query the Zoom connector to search meetings, sensitive data can pass to any of ten AI subprocessors across eight model families

3

. These findings underscore the urgent need for standardized security measures as AI agents gain access to increasingly sensitive user data and expand their capabilities to act autonomously across digital environments.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved