6 Sources
[1]
AI browsers are a cybersecurity time bomb
Web browsers are getting awfully chatty. They got even chattier last week after OpenAI and Microsoft kicked the AI browser race into high gear with ChatGPT Atlas and a "Copilot Mode" for Edge. They can answer questions, summarize pages, and even take actions on your behalf. The experience is far
[2]
AI browsers wide open to attack via prompt injection
Agentic features open the door to data exfiltration or worse Feature With great power comes great vulnerability. Several new AI browsers, including OpenAI's Atlas, offer the ability to take actions on the user's behalf, such as opening web pages or even shopping. But these added capabilities
[3]
Hidden browser extensions might be quietly recording every move you make
AI browsers risk turning helpful automation into channels for silent data theft New "agentic" browsers which offer an AI-powered sidebar promise convenience but may widen the window for deceptive attacks, experts have warned. Researchers from browser security firm SquareX found a benign-looking
[4]
AI browsers are here, and they're already being hacked
Hackers can hide code in websites to trick AI agents.Gabrielle Korein / NBC News/Getty Images AI-infused web browsers are here and they're one of the hottest products in Silicon Valley. But there's a catch: Experts and the developers of the products warn that the browsers are vulnerable to a type
[5]
AI browsers are clicking the same scams you'd never fall for
When we talk about cybersecurity, we usually imagine hackers outsmarting people. But what happens when it's AI doing the clicking instead? The new generation of AI browsers, like ChatGPT Atlas, Opera Neon, Perplexity Comet, and The Browser Company's Dia, all promise to surf the web for you. They
[6]
The Double-Edged Sword of AI Browsers: Convenience vs Security Risks
How to Find and Remove Invisible Characters from AI-Generated Text Today's AI browsers, such as those built by Opera, Perplexity, and Anthropic, integrate that let the browser act on behalf of the user. Whether it's filling out forms, summarising PDFs, or fetching data across multiple tabs, these
Share
Copy Link
New AI-powered browsers from OpenAI, Perplexity, and Opera are vulnerable to prompt injection attacks that can steal user data, access sensitive accounts, and execute malicious code. Security researchers warn these browsers are failing to detect over 90% of phishing attempts.
The rollout of AI-powered browsers has introduced a new category of cybersecurity threats that researchers warn could fundamentally compromise user safety online. Major technology companies including OpenAI, Perplexity, and Opera have launched AI browsers featuring autonomous agents capable of browsing, summarizing content, and taking actions on behalf of users
1
. However, security testing has revealed critical vulnerabilities that expose users to unprecedented risks.
Source: MakeUseOf
The primary threat facing AI browsers comes from prompt injection attacks, where malicious instructions are embedded in web content to hijack AI agents
2
. These attacks can be executed through various methods, including invisible text on websites, hidden commands in images, and fake CAPTCHA screens designed specifically to fool AI systems.
Source: NBC
Researchers at Brave Software discovered that Opera's Neon browser could be compromised by simply including invisible text on a webpage
4
. When users asked the AI agent to summarize such sites, hidden instructions could trigger the agent to access user accounts and exfiltrate email addresses to attackers.Security firm LayerX conducted comprehensive testing of multiple AI browsers and found alarming failure rates in detecting malicious content . OpenAI's Atlas browser stopped only 5.8% of malicious web pages, while Perplexity's Comet browser managed just 7% detection rate. In contrast, traditional browsers like Edge and Chrome blocked 53% and 47% of attacks respectively.
Beyond prompt injection, AI browsers face additional security challenges through cross-site request forgery attacks
2
. These attacks allow malicious websites to send commands to AI agents as if they were authenticated users, potentially accessing sensitive data across multiple sessions and devices.Researchers demonstrated that attackers could manipulate ChatGPT's memory function through these vulnerabilities, creating persistent compromises that affect users across different browsing sessions
2
. This represents a significant escalation from traditional browser security threats.Related Stories
Security researchers from SquareX identified another attack vector through malicious browser extensions that can overlay fake AI sidebars onto legitimate browsing interfaces
3
. These counterfeit interfaces can intercept user inputs and return malicious instructions while appearing completely legitimate to users.
Source: TechRadar
The attack technique uses standard extension permissions to inject JavaScript into web pages, creating overlays that capture user actions and credentials
3
. Because these extensions request commonly granted permissions, traditional security measures struggle to detect the deceptive overlays.OpenAI's Chief Information Security Officer Dane Stuckey acknowledged prompt injection as "a frontier, unsolved security problem" and warned that adversaries will invest significant resources in exploiting these vulnerabilities
4
. The company has implemented red-teaming exercises to identify vulnerabilities before public release, but researchers continue discovering new attack vectors.Professor Hamed Haddadi from Imperial College London emphasized that the rapid market deployment of AI browsers has created "a vast attack surface" without adequate security testing
1
. The competitive pressure to release AI browser features quickly has resulted in insufficient security validation, according to cybersecurity experts.Security researchers recommend treating AI browser assistants as experimental features and avoiding sensitive data handling through these platforms until stronger security measures are implemented
3
.Summarized by
Navi
[1]
[2]
20 Jul 2026•Technology

30 Jun 2026•Technology

21 Aug 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology