3 Sources
[1]
AI web browsers 'aren't ready for the public,' scientists warn as they highlight massive security red flags
By enhancing the functionality of agentic browsers, they have become insecure and could be sharing personal information. Researchers have discovered a security flaw in AI web browsers that could result in users having their data exposed by malicious websites. Browsers equipped with AI agents,
[2]
Some AI browsers come with major security risks
Some agentic AI browsers come with major cybersecurity risks, a new study finds. In the last year or so, artificial intelligence companies have rolled out a spate of web browsers equipped with AI agents. A user might ask one of these agents to plan a vacation and it will open browser tabs to
[3]
AI agent security: four July attacks, one shared flaw
In barely ten days, four separate research teams broke AI agents in four different ways. The pattern underneath them is the same, and it should worry anyone plugging a chatbot into their inbox. We spent two years asking whether AI would lie to us. The more useful question this summer is what
Share
Copy Link
Researchers from the University of Washington have uncovered critical security flaws in popular AI web browsers that bypass fundamental internet safety protocols. The study examined seven AI agentic browsers including ChatGPT Atlas and Claude for Chrome, finding that the most powerful browsers create pathways for malicious websites to steal user data through prompt injection and memory poisoning attacks.
Researchers from the University of Washington have issued a stark warning about AI security vulnerabilities in popular AI agents and AI web browsers, declaring that these tools "aren't ready for the public." In a study presented at the Agents in the Wild Workshop in Rio de Janeiro on April 26, scientists examined seven AI agentic browsers and discovered that four create pathways for malicious actors to bypass the same-origin policy, a fundamental cybersecurity protocol introduced in 1995 that prevents websites from interacting with each other's information
1
2
.
Source: Futurity
The research team successfully executed a proof-of-concept cyberattack on ChatGPT Atlas, demonstrating how a malicious website embedded within another site could steal sensitive information, similar to an advertisement on an email platform snatching data from user emails. They also identified conditions for similar attacks in Chrome with Gemini, Claude for Chrome, and Perplexity Comet
2
. "Even if you're a relatively savvy user, if these agents have access to a browser that contains your credentials -- your email, your bank account, whatever it is -- you should not trust that these systems are ready to truly protect your information," said David Kohlbrenner, assistant professor of computer science and engineering at the University of Washington1
.The study identified multiple attack surfaces that expose user data to cybersecurity risks. Prompt injection emerged as a major vulnerability, where AI agents can be tricked into misinterpreting data embedded on a malicious website as instructions they need to execute. An example scenario involves an AI agent visiting a seemingly safe site containing hidden code that instructs the browser to automatically share personal details through an auto-submitting form
1
2
.Memory poisoning represents another severe threat to AI agent security. AI agents store and consolidate information they've processed to guide future actions, making their memory contents vulnerable to data theft. "We found that some of these agents would mingle information from different origins, likely because they were revising and compressing their memory," explained Franziska Roesner, professor at the University of Washington
2
. This means a malicious instruction could persist in an agent's memory and execute later, even after initial safeguards prevented the immediate attack.
Source: Live Science
The research revealed a troubling pattern: the more capable the AI agentic browsers, the greater the security risks they pose. The team examined ChatGPT Atlas, Claude for Chrome, Brave Leo AI, Chrome with Gemini, Microsoft Edge with CoPilot, Firefox AI Mode, and Perplexity Comet, focusing on what information each agent could access from same-origin and cross-origin webpages, what actions they could undertake, and their chat context and history
1
.The findings showed no consistency in how AI web browsers operate, likely due to lack of standardization in how they interact with browser security. Several browsers could freely access cross-origin frame content while others restricted access. Some could simultaneously access multiple tabs, but most required user permission. The researchers expressed particular caution about Anthropic's Claude for Chrome, known for its strong capabilities, as well as ChatGPT Atlas and Comet, which have similarly powerful functionality
1
.Related Stories
The browser vulnerabilities represent just one facet of a larger AI security crisis. In July, four separate research teams identified critical security flaws across different AI agent implementations within roughly ten days. Security firm Manifold Security demonstrated that browser extensions could hijack Claude for Chrome and access Gmail, Google Docs, and Calendar by forging user clicks in just six lines of code. The firm reported the vulnerability to Anthropic in May, but eight releases later, the flaw remained exploitable
3
.Another study posted to arXiv showed that a single carefully crafted email could plant false memories in AI agents connected to Gmail. The poisoned memory persisted across future sessions, steering the agent's behavior without alerting the user. Meanwhile, researcher Katie Paxton-Fear at Semgrep demonstrated model poisoning for under £75, showing that just ten tainted training examples could make a model write code with hidden security holes
3
.PromptArmor's research on connectors linking ChatGPT and Claude to services like Gmail and Slack revealed a rapidly evolving threat landscape. Of 2,517 connectors tracked, 931 changed within six weeks, with connectors shifting on average every nine minutes. The Dropbox connector alone grew from eight tools to 24, with four now capable of destroying data. When users query the Zoom connector to search meetings, sensitive data can pass to any of ten AI subprocessors across eight model families
3
. These findings underscore the urgent need for standardized security measures as AI agents gain access to increasingly sensitive user data and expand their capabilities to act autonomously across digital environments.Summarized by
Navi
[1]
[2]
[3]
30 Jun 2026•Technology

30 Oct 2025•Technology

21 Aug 2025•Technology
