{"id":158858,"date":"2025-11-25T13:41:07","date_gmt":"2025-11-25T13:41:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/158858\/"},"modified":"2025-11-25T13:41:07","modified_gmt":"2025-11-25T13:41:07","slug":"new-hashjack-technique-lets-attackers-manipulate-ai-assistants-in-comet-copilot-and-gemini","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/158858\/","title":{"rendered":"New &#8216;HashJack&#8217; technique lets attackers manipulate AI assistants in Comet, Copilot and Gemini"},"content":{"rendered":"<p>A new report out today from <a href=\"https:\/\/www.catonetworks.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Cato Networks Ltd.\u2019s<\/a> Cato CTRL threat research team details a newly discovered indirect prompt injection technique that can manipulate artificial intelligence browser assistants through legitimate websites.<\/p>\n<p>Dubbed \u201cHashJack,\u201d the technique is described as the first known method that weaponizes any normal URL by hiding malicious prompts after the \u201c#\u201d symbol. The ability to do so allows attackers to influence AI assistants embedded in browsers such as Perplexity AI Inc.\u2019s Comet, Microsoft Corp.\u2019s Copilot for Edge and Google LLC\u2019s Gemini for Chrome.<\/p>\n<p>HashJack works by embedding hidden instructions inside a URL fragment, a part of the URL address that never leaves the client browser and is not logged or inspected by web servers or network tools.<\/p>\n<p>When an AI browser loads the page and the user asks a related question, the AI assistant incorporates the hidden fragment into its context window, treating it as part of the page content. The hidden fragment can trigger the assistant to generate misleading guidance, fabricate links, send users to attacker-controlled pages or, in the case of agentic AI such as Comet, execute autonomous actions such as background data fetches to malicious endpoints.<\/p>\n<p>The research outlines six attack scenarios that the technique enables, including callback phishing, data exfiltration, misinformation, malware guidance, medical-related harm and credential theft.<\/p>\n<p>In testing, Perplexity\u2019s Comet browser proved most vulnerable to HashJack, as its agentic capabilities allowed the assistant to act on the hidden instructions automatically, including sending user context such as account details or email addresses to attacker servers.<\/p>\n<p>Copilot for Edge and Gemini for Chrome also showed exploitable behaviors, though both applied some gating or link rewriting that reduced, but did not eliminate, the risk.<\/p>\n<p>Before going public with the details, the Cato CTRL threat research team reported its findings to Perplexity, Microsoft and Google over the past several months with mixed responses.<\/p>\n<p>The team said Perplexity triaged the issue as critical and applied a fix in November. Microsoft confirmed the behavior and implemented a fix in late October and emphasized its broader defense-in-depth strategy for indirect prompt injection.\u00a0Google, however, classified the behavior as intended and marked it \u201cWon\u2019t Fix,\u201d leaving Gemini for Chrome susceptible.<\/p>\n<p>The researchers argue that HashJack underscores a broader design flaw emerging in AI browsers, which routinely pass full URLs to their embedded assistants without sanitizing fragments. Because users see a trusted website and rely heavily on AI assistants for guidance, the output can appear legitimate even when it is being secretly manipulated.<\/p>\n<p>\u201cCato CTRL\u2019s findings highlight the urgent need for security frameworks that address both prompt injection risks and weaknesses in AI browser design,\u201d the report concludes. \u201cAs AI browser assistants gain access to sensitive data and system controls, the risk of context manipulation will only grow. AI browser vendors and security experts must act now, before widespread adoption makes these attacks inevitable in the real world.\u201d<\/p>\n<p>The report comes a week after browser security company <a href=\"https:\/\/siliconangle.com\/2025\/11\/19\/squarex-warns-hidden-api-perplexitys-comet-browser-enables-full-device-takeover\/\" rel=\"nofollow noopener\" target=\"_blank\">SquareX Ltd. warned<\/a> of a hidden application programming interface in Perplexity\u2019s Comet browser that allows extensions in the AI browser to execute local commands and gain full control over users\u2019 devices.<\/p>\n<p>Image: SiliconANGLE\/Ideogram<\/p>\n<p>Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE\u2019s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.<\/p>\n<p>15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more<br \/>\n11.4k+ theCUBE alumni \u2014 Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.<\/p>\n<p>About SiliconANGLE Media<\/p>\n<p>SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fsiliconangle.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=SiliconANGLE&amp;index=9&amp;md5=646b1b564e2259100a2b8638aab0a552\" rel=\"nofollow noopener\" target=\"_blank\">SiliconANGLE<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecube.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Network&amp;index=10&amp;md5=7de2a85f95ab4a4a495cede20b8cb1da\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Network<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fthecuberesearch.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Research&amp;index=11&amp;md5=7bb33676722925eb57d588ec343e4f6f\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Research<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.cube365.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=CUBE365&amp;index=12&amp;md5=d310fb35919714e66ad8d42c9c0c1bc6\" rel=\"nofollow noopener\" target=\"_blank\">CUBE365<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecubeai.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+AI&amp;index=13&amp;md5=b8b98472f8071b23ebb10ab9a8dd0683\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE AI<\/a> and theCUBE SuperStudios \u2014 with flagship locations in Silicon Valley and the New York Stock Exchange \u2014 SiliconANGLE Media operates at the intersection of media, technology and AI.<\/p>\n<p>Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.<\/p>\n","protected":false},"excerpt":{"rendered":"A new report out today from Cato Networks Ltd.\u2019s Cato CTRL threat research team details a newly discovered&hellip;\n","protected":false},"author":2,"featured_media":158859,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[89196,37894,61,60,89195,13065,80],"class_list":["post-158858","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-copilot-and-gemini","tag-duncan-riley","tag-ie","tag-ireland","tag-new-hashjack-technique-lets-attackers-manipulate-ai-assistants-in-comet","tag-siliconangle","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/158858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=158858"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/158858\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/158859"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=158858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=158858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=158858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}