# AI Browsers Can Be Hijacked by Web Pages — and Nobody Has a Real Fix
Every major AI-powered browser shipped in 2026 is vulnerable to prompt injection attacks. That was the message Artem Chaikin, a security engineer at Brave Software, brought to Black Hat USA in Las Vegas this week — and the implications land harder than most conference research drops.
Chaikin spent his session, "Attacking and Defending AI Browsers," doing something simple and devastating: he showed live demos against Opera's AI browser, the Perplexity Comet browser, and the ChatGPT Atlas browser. All of them fell. The attack surface isn't a zero-day or an obscure protocol quirk. It's the browser doing exactly what it's designed to do — reading the web — while embedded instructions tell its AI to do something else.
## The Attack Is Embarrassingly Simple
The injection vectors Chaikin demonstrated ranged from technically creative to almost insulting in their simplicity.
Against Opera, instructions were hidden inside the HTML structure of a web page — not visible to a human reader, but readable by the AI agent parsing the page. Against Perplexity Comet, he used two separate techniques: nearly invisible text overlaid on top of an image, and a Reddit comment concealed behind spoiler tags. In each case, the hidden content contained instructions that hijacked the AI's behavior.
The consequences aren't hypothetical. Indirect prompt injection through the right web page can lead to data exfiltration and account takeover. An AI browser tasked with booking a flight or checking your email isn't just reading content — it's acting on it. When a malicious page slides instructions into that workflow, the agent becomes an unwitting accomplice.
This attack class has been documented and discussed since at least 2022, but AI browsers weaponize the problem at a new scale. A traditional browser reads pages and shows them to you. An AI browser reads pages and *does things because of them.* That's a different threat surface entirely.
## Guardrails Are Necessary and Not Enough
The security industry hasn't ignored this. Chaikin catalogued the primary defenses vendors have deployed:
Individually, none of these hold. The ChatGPT Atlas browser — arguably the most defensively layered product Chaikin tested — has system-level prompting, trusted/untrusted content tagging, a secondary scanning model, and user approval prompts. It still fell.
That result deserves to sit for a moment. Atlas isn't a half-baked product. Microsoft and OpenAI have poured serious engineering into it. The failure isn't carelessness — it's a structural problem. The AI has to understand web content to be useful, and anything that can be understood can theoretically be weaponized as an instruction. The line between "data to process" and "command to obey" is exactly what the attack erases.
## Why This Problem Probably Isn't Getting Solved
Prompt injection in language models is fundamentally different from injection attacks in traditional software. SQL injection works because databases conflate data and commands in a specific, well-understood way. Developers fixed it by separating those layers — parameterized queries keep your data from being interpreted as SQL.
Prompt injection doesn't have a clean analog. The entire point of an LLM is that it understands natural language, including instructions written in natural language. You can't simply "sanitize" a web page the way you sanitize user input for a SQL query, because the attacker's payload looks like legitimate text, formatted HTML, or a normal-looking image overlay. The model has to make a judgment call about whether it's reading data or following instructions — and that judgment call can be manipulated.
Every guardrail Chaikin listed is a heuristic, not a fix. Secondary model scanning might catch known patterns; it won't catch novel ones. Human approval prompts are only as good as the human's attention and understanding of what they're approving. Untrusted content tagging requires perfect classification of what counts as untrusted — which, on the open web, approaches an impossible problem.
The vendors know this. Chaikin is presenting at Black Hat, not dropping a secret. These companies have security teams. The honest framing isn't that the industry is asleep — it's that the problem may not have a clean solution.
## What Changes When Browsers Act for You
Traditional browser security has always relied on a key assumption: a human is in the loop between seeing content and doing something with it. You see a phishing page, and you decide whether to enter your credentials. You read an email attachment, and you choose whether to open it. The human provides a friction layer.
AI browsers dissolve that friction by design. That's their value proposition — they act on your behalf. Booking, summarizing, filling forms, navigating workflows. The same capability that makes them useful makes them dangerous. When an attacker can place instructions on any web page you visit, and your browser acts on those instructions without explicitly flagging them as external commands, the friction layer is gone.
Agentic AI systems across the board share this problem. Copilots, AI assistants with web access, autonomous research tools — any system that takes actions based on content it retrieves from untrusted sources inherits this attack surface. AI browsers are just the most direct expression of it, because the entire product is "go to the web and do things."
## What Defenders Should Actually Do
The honest answer is: limit what your AI browser agents can touch. The attack is most dangerous when the agent has access to authenticated sessions, stored credentials, email, or financial accounts. Compartmentalization matters.
For enterprise deployments specifically:
For individuals, the short answer is: be aware that AI browser sessions visiting unknown sites are not the same risk profile as normal browsing.
---
## HackWire Analysis
The Chaikin presentation at Black Hat is worth treating as a milestone rather than just another vulnerability disclosure. We've seen individual prompt injection proofs-of-concept for two years. What's different now is that the attack surface has moved into a consumer product category that's actively being marketed to ordinary users.
The pattern here tracks closely with how the industry handled browser extensions in the early 2010s. Extensions could access everything — browsing history, cookies, form data — and for years the permission model was loose and poorly understood by users. The resulting ecosystem of malicious extensions and stolen credentials took years to clean up, and some of that attack surface was never really closed.
AI browsers are following the same trajectory, except the agent capability is broader and the attack requires less from the adversary. An extension attacker needed distribution — they had to get the malicious extension installed. A prompt injection attacker just needs to control a web page that the target's AI browser visits. That's a dramatically lower bar.
What's being missed in most coverage of this research: the secondary scanning model defense Chaikin tested — and which still failed against Atlas — is the approach most vendors will lean into. Expect a wave of "we've improved our AI safety scanning" announcements over the next six to twelve months that solve known patterns while leaving novel injection techniques wide open. The research is ahead of the mitigations, and will likely stay there.
Enterprise security teams should be having this conversation now, before AI browsers become standard-issue tooling the way Chrome did in the early 2010s — and before the first major breach via this vector makes the conversation mandatory.
— HackWire Editorial
---
## Related Coverage