{"id":86801,"date":"2025-08-23T06:15:16","date_gmt":"2025-08-23T06:15:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/86801\/"},"modified":"2025-08-23T06:15:16","modified_gmt":"2025-08-23T06:15:16","slug":"change-your-browser-settings-now-google-beaten-by-ai-attacks","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/86801\/","title":{"rendered":"Change Your Browser Settings Now\u2014Google Beaten By AI Attacks"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/08\/1755929716_3_960x0.jpg\" alt=\"Internet Hacking Photo Illustrations\" data-height=\"2356\" data-width=\"3535\" style=\"position:absolute;top:0\"\/><\/p>\n<p>These new attacks break the internet.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>The internet is not a safe space and it\u2019s about to get worse. A new \u201cattack surface is far wider than anything we\u2019ve faced before,\u201d with \u201chidden risks\u201d that \u201ccompromise millions of users simultaneously.\u201d And Google\u2019s defenses are \u201cunfortunately insufficient.\u201d<\/p>\n<p>That\u2019s the warning from <a class=\"color-link\" href=\"https:\/\/guard.io\/labs\/scamlexity-we-put-agentic-ai-browsers-to-the-test-they-clicked-they-paid-they-failed\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/guard.io\/labs\/scamlexity-we-put-agentic-ai-browsers-to-the-test-they-clicked-they-paid-they-failed\" aria-label=\"Guardio\">Guardio<\/a>, which has set out to understand just how exposed we are by new AI browsing tools and the extent to which they put us all at risk. The results are alarming. It is \u201ca perfect trust chain gone rogue,\u201d the team says, and you need to shore up your personal defenses before it\u2019s too late.<\/p>\n<p class=\"p1\">While \u201cAI Browsers <a class=\"color-link\" href=\"https:\/\/www.theregister.com\/2025\/08\/19\/palo_alto_networks_q4_fy25\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.theregister.com\/2025\/08\/19\/palo_alto_networks_q4_fy25\/\" aria-label=\"promise a future\">promise a future<\/a> where Agentic AI works for you, fully automating online tasks from shopping to handling emails.\u201d this convenience &#8220;comes with a cost.&#8221; The team set up three tests: instructing AI to find and buy a product online, allowing AI to open a banking sign-in page, and a new spin on the viral <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/21\/do-not-click-if-you-see-this-on-your-pc-its-an-attack\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/04\/21\/do-not-click-if-you-see-this-on-your-pc-its-an-attack\/\" target=\"_self\" aria-label=\"ClickFix\" rel=\"nofollow noopener\">ClickFix<\/a> attack.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/20\/delete-every-app-thats-on-this-list-your-phone-will-be-tracked\/\" target=\"_blank\" aria-label=\"Delete Every App That\u2019s On This List\u2014Your Phone Will Be Tracked\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/20\/delete-every-app-thats-on-this-list-your-phone-will-be-tracked\/\" rel=\"nofollow noopener\">ForbesDelete Every App That\u2019s On This List\u2014Your Phone Will Be TrackedBy Zak Doffman<\/a><\/p>\n<p class=\"p1\">In each case, the AI agent put its human at risk \u2014 and these attacks are not sophisticated. Almost all humans would have detected these threats. And that\u2019s the key message here \u2014 AI is too easily fooled, and this attack surface is so new, that more sophisticated adversaries are only just getting started.<\/p>\n<p class=\"p1\">\u201cAI Browsers are no longer a concept,&#8221; Guardio says. &#8220;Microsoft has Copilot built into Edge. OpenAI is experimenting with a sandboxed browser in \u2018agent mode\u2019. And Perplexity\u2019s Comet fully embraces the idea of a browser that browses for you. Searching, reading, shopping, clicking. It\u2019s not just assisting us, but increasingly replacing us.&#8221;<\/p>\n<p class=\"p1\">In the first test, a fake Walmart online store was spun up. \u201cThe site had everything: a clean design, realistic product listings, and a checkout flow good enough to pass a casual glance.\u201d Within the AI browser \u201cthe page loads without issue and isn\u2019t blocked by Google Safe Browsing, even though GSB is active in this Chromium-based browser.\u201d<\/p>\n<p class=\"p1\">The AI agent was told to buy an Apple Watch and it did exactly that. \u201cIt found the Apple Watch, added it to the cart, and, without asking for confirmation, autofilled our saved address and credit card details.\u201d Seconds later \u201cthe purchase was complete.&#8221; There is no watch, of course, just opportunistic scammers \u201calready spending their money.\u201d<\/p>\n<p class=\"p1\">The test didn\u2019t always succeed, sometimes the AI was not fooled \u2014 but it was fooled plenty of times. \u201cAnd when security depends on chance, it\u2019s not security.\u201d<\/p>\n<p class=\"p1\">In the second test, the AI browser was directed by a phishing email to a fake Wells Fargo sign-in page. \u201cThere was no URL check, no pre-navigation warning, just a direct pass to the attacker\u2019s page. Once the fake Wells Fargo login loaded, the browser treated it as legitimate. It prompted the user to enter credentials, even helping fill in the form.\u201d<\/p>\n<p class=\"p1\">The third test expanded on the new prompt injection threat, with these hidden behind a typical ClickFix popup, in this case a Captcha, but one with hidden instructions for the AI agent to ignore what was visible to the human and run a different script instead.<\/p>\n<p class=\"p1\">\u201cWe don\u2019t try to glitch the model into obedience,\u201d Guardio says. \u201cInstead, we mislead it using techniques borrowed from the human social engineering playbook \u2014 appealing directly to its core design goal: to help its human quickly, completely, and without hesitation. We just provide it with the best (manipulating) methods to do so.\u201d<\/p>\n<p class=\"p1\">Guardio warns that \u201cin the AI-vs-AI era, scammers don\u2019t need to trick millions of different people; they only need to break one AI model. Once they succeed, the same exploit can be scaled endlessly. And because they have access to the same models, they can \u201ctrain\u201d their malicious AI against the victim\u2019s AI until the scam works flawlessly.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/20\/google-issues-emergency-security-update-for-all-chrome-users\/\" target=\"_blank\" aria-label=\"Google Issues Emergency Security Update For All Chrome Users\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/08\/20\/google-issues-emergency-security-update-for-all-chrome-users\/\" rel=\"nofollow noopener\">ForbesGoogle Issues Emergency Security Update For All Chrome UsersBy Zak Doffman<\/a><\/p>\n<p class=\"p1\">This works because \u201csecurity is often an afterthought or delegated entirely to existing tools like Google Safe Browsing, which is, unfortunately, insufficient.\u201d Even the fake Wells Fargo sign-in page, which was \u201cactive in the wild for several days,\u201d was \u201cstill unflagged by <a class=\"color-link\" href=\"https:\/\/support.google.com\/chrome\/answer\/9890866?sjid=340450356576507172-EU\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/chrome\/answer\/9890866?sjid=340450356576507172-EU\" aria-label=\"Google Safe Browsing\">Google Safe Browsing<\/a>.\u201d<\/p>\n<p class=\"p1\">The advice is simple. If you use an AI agent and give it free rein, then change your browser settings to apply <a class=\"color-link\" href=\"https:\/\/support.google.com\/chrome\/answer\/9890866?sjid=340450356576507172-EU#zippy=%2Cenhanced-protection\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/chrome\/answer\/9890866?sjid=340450356576507172-EU#zippy=%2Cenhanced-protection\" aria-label=\"Enhanced Protection\">Enhanced Protection<\/a>. If this isn\u2019t available, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/03\/change-your-browser-settings-now-massive-security-risk\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/07\/03\/change-your-browser-settings-now-massive-security-risk\/\" target=\"_self\" aria-label=\"change your browser\" rel=\"nofollow noopener\">change your browser<\/a>. You also need to be careful with browser-based password managers, saved credit card details and autofill. If you allow your AI agent to tap into your security credentials and your financial information, then you\u2019re out on thin ice.<\/p>\n<p class=\"p1\">In a world where Google controls the internet, directing us and our AI agents to the websites we visit, then Google\u2019s defenses protect the internet. If they don\u2019t work, then the internet doesn\u2019t work. A rethink is required before it\u2019s too late.<\/p>\n<p class=\"p1\">I have reached out to Google for any comments on this new report.<\/p>\n","protected":false},"excerpt":{"rendered":"These new attacks break the internet. NurPhoto via Getty Images The internet is not a safe space and&hellip;\n","protected":false},"author":2,"featured_media":86802,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,43679,43676,43677,43675,43674,43680,43678,86,56,54,55],"class_list":["post-86801","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-comet-vs-chrome","tag-google-ai-upgrade","tag-google-attack-chrome-attack","tag-google-chrome-update","tag-google-security","tag-openai-browser","tag-perplexity-vs-google","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/86801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=86801"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/86801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/86802"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=86801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=86801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=86801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}