Use AI browsers? Be careful. This exploit turns trusted sites into weapons - heres how

General News

Summary

Researchers uncovered HashJack, a prompt-injection attack that targets AI browsers through hidden instructions in URL fragments. The technique can turn trusted websites into delivery mechanisms for phishing links, malware, misinformation, and even data theft. The issue affects AI browser assistants such as Comet, Copilot for Edge, and Gemini for Chrome, and it can bypass traditional defenses because the malicious content stays in the fragment portion of the URL. Google, Microsoft, and Perplexity have already reviewed or addressed the reported issue. The finding highlights a growing security risk for agentic AI browsing tools that automatically process page content and full URLs.

Classifications

industries
No industries detected
applications
ERP & Process Management

AskAI Classifications

Labels
Network Security SaaS Cloud Security

Linked Companies

Cato Networks
$50M to $100M