3 Sources
[1]
Microsoft's plan to fix the web with AI has already hit an embarrassing security flaw
Researchers have already found a critical vulnerability in the new NLWeb protocol Microsoft made a big deal about just just a few months ago at Build. It's a protocol that's supposed to be "HTML for the Agentic Web," offering ChatGPT-like search to any website or app. Discovery of the embarrassing
[2]
Microsoft's agentic HTML can leak passwords and AI keys, researcher finds
Microsoft has issued a patch, and there's nothing you need to do. With new AI systems comes new AI vulnerabilities, and a big one was just discovered. It's a flaw in Microsoft's method of allowing agents to interact with websites on your behalf. Microsoft calls this technique NLWeb, which is a
[3]
Microsoft's agentic AI roadmap had a flaw that let hackers take over browsers -- here's what to know and how to stay safe
Microsoft is quickly heading towards AI agentic browsing -- that much is obvious with Edge's AI makeover and an open project called NLWeb that can be used to give any website AI power. But while this all sounds good on paper, it does open the door to a whole lot of security risks, and the
Share
Copy Link
A critical vulnerability discovered in Microsoft's NLWeb protocol, designed for AI-powered web interactions, has exposed potential security risks in the emerging field of agentic web browsing.
Microsoft's ambitious plan to revolutionize the web with AI-powered interactions has encountered a significant setback. Researchers have uncovered a critical security flaw in the recently unveiled NLWeb protocol, which Microsoft touted as "HTML for the Agentic Web"
1
. This protocol, designed to enable ChatGPT-like search capabilities for websites and applications, was introduced just months ago at Microsoft's Build conference.
Source: The Verge
The vulnerability, discovered by security researchers Aonan Guan and Lei Wang, allows remote users to access sensitive files, including system configuration files and API keys for services like OpenAI and Google Gemini
2
. What makes this flaw particularly concerning is its simplicity – it's a classic path traversal vulnerability that can be exploited by visiting a malformed URL1
.The discovery of this security flaw is especially embarrassing for Microsoft, given the company's recent emphasis on security. It raises questions about the thoroughness of Microsoft's security practices in developing new AI-powered systems
1
. The vulnerability has potentially far-reaching consequences:2
.1
.1
.Microsoft has addressed the vulnerability by issuing a patch on July 1st, 2023, updating the open-source repository
3
. However, the company has not issued a CVE (Common Vulnerabilities and Exposures) for the issue, which is an industry standard for classifying vulnerabilities1
. This decision has been met with some criticism from security researchers who argue that a CVE would help alert more people to the fix and allow for better tracking.Related Stories

Source: Tom's Guide
This incident highlights the potential risks associated with the rapid development and deployment of AI-powered web technologies:
2
.3
.3
.The incident serves as a wake-up call for the tech industry as it races to integrate AI into web technologies. Microsoft's push for native support of the Model Context Protocol (MCP) in Windows, despite warnings from security researchers, further underscores the tension between rapid innovation and security concerns
1
.
Source: PCWorld
As the landscape of AI-powered web interactions evolves, it's clear that companies will need to strike a careful balance between rolling out new features and maintaining stringent security protocols. The NLWeb vulnerability serves as a critical reminder of the potential risks associated with these emerging technologies and the importance of thorough security testing in the development of AI-powered systems.
Summarized by
Navi
20 Jul 2026•Technology

30 Jun 2026•Technology

12 Jun 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology