SOFTWARE AND UPDATES AI browser agents bypass same-origin policy, exposing user data to prompt injection GAMES God of War Creator David Jaffe Blames Ninja Theory’s Potential Closure on ‘Artistic’ Ambitions GAMES Graveyard Keeper 2 Surpasses 53,000 Concurrent Viewers on Launch Day GAMES Escape from Tarkov PvE Prestige Adds Exclusive NKVD Finka and Shark Knife Rewards PLAYSTATION 5 GTA VI Actress Manni L. Perez Deletes Post After 18 Million Views Spark Casting Rumors GAMES The Sims 4 Update Fixes Robotic AI With Eye Contact and Hand Washing PLAYSTATION 5 Amazon Destroys 450 PlayStation 5 Game Discs as Sony Shifts to Digital PLAYSTATION 5 GTA VI release triggers $1 billion economic damage forecast as workers take November off GAMES Bulkhead Wardogs price jumps to $50 then $60 as early access matures CONSOLES Sony survey suggests reconsideration of January 2028 disc discontinuation NINTENDO SWITCH 2 Ubisoft confirms Beyond Good & Evil 2 is still in development 18 years after original announcement GAMES Cosplayer Katssby Brings The Witcher 3’s Fringilla Vigo to Life in Stunning Photoshoot GAMES Bethesda grants Obsidian creative independence for new Fallout title GAMES Remedy removes stamina limits and technical bugs from Control Resonant movement

AI browser agents bypass same-origin policy, exposing user data to prompt injection

Lena Fischer 0 comments 3 min read

Security researchers found that AI browser agents can bypass the same- origin policy, allowing prompt injection attacks to steal data from other tabs.

AI browser agents bypass same-origin policy, exposing user data to prompt injection
SOFTWARE AND UPDATES

Security researchers have exposed critical flaws in how AI-enabled browsers handle sensitive web data, revealing that these tools can bypass fundamental browser safety barriers. The findings matter because users rely on these agents to automate tasks across multiple sites, assuming their credentials and private information remain isolated. We now know that this assumption is often wrong, as prompt injection attacks can trick the AI into stealing data from other tabs or sending messages without consent.

Study reveals AI agents can steal cross-origin data and bypass safety barriers

The vulnerabilities were identified in several popular AI browser integrations, including ChatGPT Atlas, Claude for Chrome, Edge with Copilot, Brave Leo AI, Firefox AI Mode, and Perplexity Comet. These tools operate as browser agents that can interact with web pages on behalf of the user, effectively acting as a second layer of navigation. Researchers from the University of Washington, Duke University, Stanford University, and Berkeley tested these agents to see how they enforced the same-origin policy, which is designed to keep data separate between different websites.

In the University of Washington study, ChatGPT Atlas in agent mode was the only browser successfully attacked for cross-origin data theft. The researchers noted that in such cases, the strength of the same-origin policy is reduced to the strength of the agent's defenses against prompt injections. Claude for Chrome presented a different risk, allowing JavaScript injection and reading masked password fields via direct Document Object Model access. These technical failures mean that the AI could extract information that the browser itself would normally block from other origins.

Zenity Labs demonstrated a practical phishing attack using Atlas where it sent messages from a victim's WhatsApp despite flagging the action as sensitive. Atlas had flagged WhatsApp as sensitive the whole time and kept the workflow ribbon red. It sent every message anyway. This behavior highlights a disconnect between the agent's internal safety classifiers and its actual execution logic. Meanwhile, Brave uses an isolated browsing profile for AI agents, while other vendors rely on soft classifiers or permission prompts, creating an uneven security landscape across the market.

OpenAI shut down ChatGPT Atlas on August 9, 2026, moving features to the desktop app with different security boundaries. This change suggests that the company recognized the risks associated with the browser-integrated agent mode. The part that would catch the described case had not shipped at the time of the test. There is no statement on whether it has shipped since. Users should verify which version of their AI browser they are using and understand that agent capabilities may still carry significant privacy risks.

The core takeaway is that AI browser agents are not yet reliable guardians of your session data. The same-origin policy, a cornerstone of web security, is effectively disabled when the AI can be tricked by malicious prompts. Buyers who rely on these tools for automating sensitive tasks should proceed with caution. The industry needs stronger architectural solutions than soft classifiers to ensure that AI agents do not become vectors for data theft.

Source: NotebookCheck

Discussion

0 comments

Leave a comment