University of Washington Study Finds Major Security Flaws in AI Browser Agents

graphical user interface, text

New research from the University of Washington has found that several popular AI-powered agentic browsers carry significant cybersecurity vulnerabilities, undermining a foundational web security protocol known as the same-origin policy. The study examined seven agentic browsers and found that four, including ChatGPT Atlas, Chrome with Gemini, Claude for Chrome, and Perplexity Comet, created conditions allowing malicious actors to bypass the protections that normally prevent websites from accessing each other’s data.

Researchers successfully demonstrated a proof-of-concept attack on ChatGPT Atlas, in which one website was able to extract sensitive information from another embedded within it. Browsers granting AI agents fewer permissions were generally found to be safer, with Firefox AI Mode emerging as the least risky option tested, though also the most limited in capability.

David Kohlbrenner, a University of Washington assistant professor and co-senior author of the study, said browser agents with access to sensitive credentials should not yet be trusted to protect user information. Co-senior author Franziska Roesner noted that the same-origin policy has underpinned safe web browsing for three decades, and that the vulnerabilities identified represent a meaningful regression in browser security.

The researchers identified two primary attack vectors: prompt injection, where hidden instructions embedded in malicious webpages manipulate an agent’s behaviour, and memory poisoning, where an agent’s stored information becomes vulnerable to cross-contamination between different website origins.

The findings were shared with the companies involved; Anthropic and Firefox did not respond, while Perplexity and OpenAI declined to comment.

Need Deeper Intelligence on the AI Market?

AI Insider's Market Intelligence platform tracks funding rounds, competitive landscapes, and technology trends across the global AI ecosystem in real time. Get the data and insights your organization needs to make informed decisions.

Related Articles

IBM Partners With OpenAI to Expand Enterprise AI Deployment Through Global Consulting Business

IBM announced a new partnership with OpenAI to bring the AI company’s models and tools to more enterprise clients through IBM’s global consulting arm, deepening

Databricks Announces $5B in Funding at $190B Valuation, Fueled by Massive Investor Demand

Databricks has closed a $5 billion funding round led by Coatue, with participation from Blackstone, MGX, T. Rowe Price affiliates, new investor Sixth Street Growth,

the open ai logo is displayed on a computer screen
OpenAI Names New Chief Revenue Officer in Executive Shake-Up, Launches Ultrafast Processing Mode

OpenAI has replaced chief revenue officer Denise Dresser after just nine months, appointing Dali Rajic, former president and chief operating officer of Wiz, to lead

Stay Updated with AI Insider

Get the latest AI funding news, market intelligence, and industry insights delivered to your inbox weekly.

$ 0 M

Seed round tracked

Gitar — Code Validation

Get the Weekly Briefing

Funding analysis, market intelligence, and industry trends delivered to your inbox every week.

Need bespoke intelligence?

Our team combines real-time data with decades of sector experience to guide your decisions.

Subscribe today for the latest news about the AI landscape