{"id":92430,"date":"2025-08-25T20:41:06","date_gmt":"2025-08-25T20:41:06","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/92430\/"},"modified":"2025-08-25T20:41:06","modified_gmt":"2025-08-25T20:41:06","slug":"ai-browsers-could-leave-users-penniless-a-prompt-injection-warning","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/92430\/","title":{"rendered":"AI browsers could leave users penniless: A prompt injection warning"},"content":{"rendered":"<p>Artificial Intelligence (AI) browsers are gaining traction, which means we may need to start worrying about the potential dangers of something called \u201cprompt injection.\u201d<\/p>\n<p>Large language models (LLMs)\u2014like the ones that power AI chatbots including ChatGPT, Claude, and Gemini\u2014are designed to follow \u201cprompts,\u201d which are the instructions and questions that people provide when looking up info or getting help with a topic. In a chatbot, the questions you ask the AI are the \u201cprompts.\u201d But AI models aren\u2019t great at telling apart the types of commands that are meant for their eyes only (for example, hidden background rules that come directly from developers, like \u201c<a href=\"https:\/\/www.threatdown.com\/blog\/will-chatgpt-write-ransomware-yes\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">don\u2019t write ransomware<\/a>\u201c) from the types of requests that come from users.<\/p>\n<p>To showcase the risks here, the web browser developer Brave\u2014which has its own AI assistant called Leo\u2014recently tested whether it could trick an AI browser into reading dangerous prompts that harm users. And what the company found caused alarm, as they wrote in a <a href=\"https:\/\/brave.com\/blog\/comet-prompt-injection\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">blog this week<\/a>:<\/p>\n<p>\u201cAs users grow comfortable with AI browsers and begin trusting them with sensitive data in logged in sessions\u2014such as banking, healthcare, and other critical websites\u2014the risks multiply. What if the model hallucinates and performs actions you didn\u2019t request? Or worse, what if a benign-looking website or a comment left on a social media site could steal your login credentials or other sensitive data by adding invisible instructions for the AI assistant?\u201d<\/p>\n<p>Prompt injection, then, is basically a trick where someone inserts carefully crafted input in the form of an ordinary conversation or data, to nudge or outright force an AI into doing something it wasn\u2019t meant to do.<\/p>\n<p>What sets prompt injection apart from old-school hacking is that the weapon here is language, not code. Attackers don\u2019t need to break into servers or look for traditional software bugs, they just need to be clever with words.<\/p>\n<p>For an AI browser, part of the input is the content of the sites it visits. So, it\u2019s possible to hide indirect prompt injections inside web pages by embedding malicious instructions in content that appears harmless or invisible to human users but is processed by AI browsers as part of their command context.<\/p>\n<p>Now we need to define the difference between an AI browser and an agentic browser. An AI browser is any browser that uses artificial intelligence to assist users. This might mean answering questions, summarizing articles, making recommendations, or helping with searches. These tools support the user but usually need some manual guidance and still rely on the user to approve or complete tasks.<\/p>\n<p>But, more recently, we are seeing the rise of agentic browsers, which are a new type of web browser powered by artificial intelligence, designed to do much more than just display websites. These browsers are designed to actually take over entire workflows, executing complex multi-step tasks with little or no user intervention, meaning they can actually use and interact with sites to carry out tasks for the user, almost like having an online assistant. Instead of waiting for clicks and manual instructions, agentic browsers can navigate web pages, fill out forms, make purchases, or book appointments on their own, based on what the user wants to accomplish.<\/p>\n<p>For example, when you tell your agentic browser, \u201cFind the cheapest flight to Paris next month and book it,\u201d the browser will do all the research, compare prices, fill out passenger details, and complete the booking without any extra steps or manual effort\u2014provided it has all the necessary details of course, which are part of the prompts the user feeds the agentic browser.<\/p>\n<p>Are you seeing the potential dangers of prompt injections here?<\/p>\n<p>What if my agentic browser gets new details while visiting a website? I can imagine criminals setting up a website with extremely competitive pricing just to attract visitors, but the real goal is to extract the payment information which the agentic browser needs to make purchases on your behalf. You could end up paying for someone else\u2019s vacation to France.<\/p>\n<p>During their research, Brave found that Perplexity\u2019s Comet has some vulnerabilities which \u201cunderline the security challenges faced by agentic AI implementations in browsers.\u201d<\/p>\n<p>The vulnerabilities allow an attack based on indirect prompt injection, which means the malicious instructions are embedded in external content (like a website, or a PDF) that the browser AI assistant processes as part of fulfilling the user\u2019s request. There are various ways of hiding that malicious content from a casual inspection. Brave uses the example of white text on a white background which AI browsers have no problem reading and a human would not see without closer inspection.<\/p>\n<p>To <a href=\"https:\/\/x.com\/zack_overflow\/status\/1959308058200551721\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">quote a user on X<\/a>:<\/p>\n<p>\u201cYou can literally get prompt injected and your bank account drained by doomscrolling on reddit\u201d<\/p>\n<p>To prevent this type of prompt injection, it is imperative that agentic browsers understand the difference between user-provided instructions and web content processed to fulfill the instructions and treat them accordingly.<\/p>\n<p>Perplexity has attempted twice to fix the vulnerability reported by Brave, but it still hasn\u2019t fully mitigated this kind of attack as of the time of this reporting.<\/p>\n<p>Safe use of agentic browsers<\/p>\n<p>While it\u2019s always tempting to use the latest gadgets this comes with a certain amount of risk. To limit those risks when using agentic browsers you should:<\/p>\n<p>Be cautious with permissions:\u00a0Only grant access to sensitive information or system controls when absolutely necessary. Review what data or accounts the agentic browser can access and limit permissions where possible.<\/p>\n<p>Verify sources before trusting links or commands:\u00a0Avoid letting the browser automatically interact with unfamiliar websites or content. Check URLs carefully and be wary of sudden redirects or unexpected input requests.<\/p>\n<p>Keep software updated:\u00a0Ensure the agentic browser and related AI tools are always running the latest versions to benefit from security patches and improvements against prompt injection exploits.<\/p>\n<p>Use strong authentication and monitoring:\u00a0Protect accounts connected to agentic browsers with multi-factor authentication and review activity logs regularly to spot unusual behavior early.<\/p>\n<p>Educate yourself about prompt injection risks:\u00a0Stay informed on the latest threats and best practices for safe AI interactions. Being aware is the first step to preventing exploitation.<\/p>\n<p>Limit sensitive operations automation:\u00a0Avoid fully automating high-stakes transactions or actions without manual review. Agentic browsers should assist, but critical decisions benefit from human oversight. For example: limit the amount of money it can spend without your explicit permission or always let it ask you to authorize payments.<\/p>\n<p>Report suspicious behavior:\u00a0If an agentic browser acts unpredictably or asks for strange permissions, report it to the developers or security teams immediately for investigation.<\/p>\n<p>We don\u2019t just report on threats\u2014we remove them<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/for-home\" rel=\"nofollow noopener\" target=\"_blank\">downloading Malwarebytes today<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Artificial Intelligence (AI) browsers are gaining traction, which means we may need to start worrying about the potential&hellip;\n","protected":false},"author":2,"featured_media":92431,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[46000,554,23704,733,4308,46001,86,56,54,55],"class_list":["post-92430","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-agentic-browser","tag-ai","tag-ai-browser","tag-artificial-intelligence","tag-artificialintelligence","tag-prompt-injection","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/92430","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=92430"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/92430\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/92431"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=92430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=92430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=92430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}