Use AI browsers? Be careful. This exploit turns trusted sites into weapons - heres how
Summary
Researchers uncovered HashJack, a prompt-injection attack that targets AI browsers through hidden instructions in URL fragments. The technique can turn trusted websites into delivery mechanisms for phishing links, malware, misinformation, and even data theft. The issue affects AI browser assistants such as Comet, Copilot for Edge, and Gemini for Chrome, and it can bypass traditional defenses because the malicious content stays in the fragment portion of the URL. Google, Microsoft, and Perplexity have already reviewed or addressed the reported issue. The finding highlights a growing security risk for agentic AI browsing tools that automatically process page content and full URLs.
Classifications
industries
No industries detected
applications
ERP & Process Management
AskAI Classifications
Labels
Network Security
SaaS
Cloud Security
Linked Companies
Cato Networks
$50M to $100M