AI Browsers Face Growing Cybersecurity Threats as Major Tech Companies Rush to Market

Reviewed byNidhi Govil

2 Sources

Share

New AI-powered browsers from OpenAI, Microsoft, and other companies are introducing significant security vulnerabilities, including prompt injection attacks and malicious extensions that can steal user data and hijack browser functions.

AI Browser Security Crisis Emerges

The race to integrate artificial intelligence into web browsers has taken a dangerous turn, with cybersecurity experts warning of a "cybersecurity time bomb" as major vulnerabilities emerge across multiple AI-powered browsing platforms

1

. Recent weeks have seen the discovery of critical security flaws in prominent AI browsers, including OpenAI's ChatGPT Atlas, Microsoft's Copilot Mode for Edge, and Perplexity's Comet browser.

Source: The Verge

Source: The Verge

Researchers have uncovered vulnerabilities in Atlas that allow attackers to exploit ChatGPT's memory function to inject malicious code, grant unauthorized access privileges, and deploy malware

1

. Similarly, flaws in Comet could enable attackers to hijack the browser's AI with hidden instructions, fundamentally compromising the user experience.

The Expanding AI Browser Landscape

The current security crisis stems from a broader industry push to control the gateway to the internet by embedding AI directly into browsers

1

. Beyond OpenAI and Microsoft, established players like Google are integrating Gemini AI into Chrome, Opera has launched Neon, and The Browser Company has introduced Dia. Startups are also competing aggressively, with Perplexity making its Comet browser freely available and Sweden's Strawberry targeting "disappointed Atlas users."

This rapid expansion has created what Hamed Haddadi, professor at Imperial College London and chief scientist at Brave, describes as "a vast attack surface" despite heavy guardrails being in place

1

.

Sophisticated Extension-Based Attacks

A particularly concerning threat has emerged through malicious browser extensions that can create convincing fake AI sidebars

2

. Researchers from SquareX discovered that benign-looking extensions can overlay counterfeit sidebars onto browsing surfaces, intercept user inputs, and return malicious instructions that appear legitimate.

Source: TechRadar

Source: TechRadar

These attacks use extension features to inject JavaScript into web pages, rendering fake sidebars that capture user actions while mimicking standard interaction flows

2

. The technique can direct users to phishing sites, capture OAuth tokens through fake file-sharing prompts, and recommend commands that install remote access backdoors.

Privacy and Data Collection Concerns

AI browsers pose unprecedented privacy risks due to their extensive data collection capabilities. Yash Vekaria, a computer science researcher at UC Davis, notes that these browsers are "much more powerful than traditional browsers" and create "an imminent risk from being tracked and profiled"

1

.

AI memory functions are designed to learn from everything users do, including browsing habits, emails, searches, and conversations with built-in AI assistants. This creates what Vekaria describes as "a more invasive profile than ever before," which becomes particularly valuable to hackers when coupled with stored credit card details and login credentials

1

.

Market Rush vs. Security Testing

Cybersecurity experts point to the rapid market deployment as a primary concern. Lukasz Olejnik, an independent cybersecurity researcher at King's College London, warns that "it's early days, so expect risky vulnerabilities to emerge," drawing parallels to previous security issues with Office macros, malicious browser extensions, and early mobile platforms

1

.

Hamed Haddadi identifies "the market rush" as the biggest immediate threat, noting that "these agentic browsers have not been thoroughly tested and validated"

1

. This rushed deployment increases the likelihood of zero-day attacks, where vulnerabilities remain undiscovered until exploited maliciously.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo