started · updated
AI-Powered Web Browsers Pose Security Risks, Study Finds
Researchers at the University of Washington evaluated seven popular AI‑enhanced web browsers and discovered that four of them could be exploited to bypass the long‑standing same‑origin policy, exposing users’ cross‑site data. The team demonstrated a successful attack on the ChatGPT Atlas browser, showing that a malicious site can steal information from another site displayed in the same window. Similar vulnerabilities were identified in Chrome with Gemini, Claude for Chrome, and Perplexity Comet.
The study highlights additional threats such as prompt injection—where hidden instructions coax the AI to reveal private data—and memory poisoning, where malicious cues stored in the AI’s short‑term memory can cause later leaks. While some browser vendors engaged with the researchers, others have not acknowledged the report. No definitive mitigation is yet available, and users are advised to limit AI agents’ access to sensitive accounts until stronger safeguards are implemented.