University of Washington Study Finds Major Security Flaws in AI Browser Agents

graphical user interface, text

New research from the University of Washington has found that several popular AI-powered agentic browsers carry significant cybersecurity vulnerabilities, undermining a foundational web security protocol known as the same-origin policy. The study examined seven agentic browsers and found that four, including ChatGPT Atlas, Chrome with Gemini, Claude for Chrome, and Perplexity Comet, created conditions allowing malicious actors to bypass the protections that normally prevent websites from accessing each other’s data.

Researchers successfully demonstrated a proof-of-concept attack on ChatGPT Atlas, in which one website was able to extract sensitive information from another embedded within it. Browsers granting AI agents fewer permissions were generally found to be safer, with Firefox AI Mode emerging as the least risky option tested, though also the most limited in capability.

David Kohlbrenner, a University of Washington assistant professor and co-senior author of the study, said browser agents with access to sensitive credentials should not yet be trusted to protect user information. Co-senior author Franziska Roesner noted that the same-origin policy has underpinned safe web browsing for three decades, and that the vulnerabilities identified represent a meaningful regression in browser security.

The researchers identified two primary attack vectors: prompt injection, where hidden instructions embedded in malicious webpages manipulate an agent’s behaviour, and memory poisoning, where an agent’s stored information becomes vulnerable to cross-contamination between different website origins.

The findings were shared with the companies involved; Anthropic and Firefox did not respond, while Perplexity and OpenAI declined to comment.

Need Deeper Intelligence on the AI Market?

AI Insider's Market Intelligence platform tracks funding rounds, competitive landscapes, and technology trends across the global AI ecosystem in real time. Get the data and insights your organization needs to make informed decisions.

Related Articles

UK’s Humanoid Raises $152M in Series A Funding at $1.35B Valuation for Humanoid Robots

Insider Brief Humanoid has raised $152 million in Series A funding to develop and deploy industrial humanoid robots. According to the UK-based Ai and robotics

a large building with steps leading up to it
Head of U.S. AI Standards Agency CAISI Resigns After Three Months on the Job

Chris Fall, director of the Center for AI Standards and Innovation (CAISI), has resigned, according to the agency. Fall had led the organization for just

a blurry photo of a colorful object
Google Reportedly Developing New AI Chip Aimed at Boosting Gemini Model Efficiency

Alphabet, Google’s parent company, is reportedly developing a new server chip designed to improve the efficiency of its in-house Gemini AI models. The chip, internally referred to

Stay Updated with AI Insider

Get the latest AI funding news, market intelligence, and industry insights delivered to your inbox weekly.

$ 0 M

Seed round tracked

Gitar — Code Validation

Get the Weekly Briefing

Funding analysis, market intelligence, and industry trends delivered to your inbox every week.

Need bespoke intelligence?

Our team combines real-time data with decades of sector experience to guide your decisions.

Subscribe today for the latest news about the AI landscape