Skip to main content
  1. Home
  2. Computing
  3. News

Yet another research breaks the hype bubble for AI browsers serving serious security flaws

Four popular AI browsers can be exploited to steal your data from other open tabs.

Add as a preferred source on Google
ChatGPT Atlas browser on a MacBook.
Nadeem Sarwar / Digital Trends

AI browsers are being sold as the next big thing. They can summarize pages, book trips, and even make purchases for you. But a new study from the University of Washington found that four of the seven most popular ones come with a security risk serious enough to let malicious websites steal data from other sites you have open. The more capable the browser, the bigger the risk turns out to be.

The 30-year security rule that AI browsers are breaking

Since 1995, every browser has followed a rule called the same-origin policy, which prevents websites from reading each other’s data. If you have your bank open in one tab and visit a sketchy site in another, that sketchy site cannot touch your banking information. AI browsers need to bypass this rule to function, since completing tasks across multiple tabs requires reading across different sites.

Recommended Videos

That broader access is exactly what attackers can exploit through two methods. The first is prompt injection, where a malicious webpage hides secret instructions that the AI agent follows without realizing it has been manipulated, potentially exposing your private emails, passwords, or calendar details.

The second method is memory poisoning, where planted instructions get stored in the agent’s memory and activate later, even after the original page is closed. Researchers ran a successful proof-of-concept attack on ChatGPT Atlas, demonstrating the risk is real. Claude for Chrome was flagged as particularly risky because its browser extension design lets it inject code directly into webpages.

Which AI browsers are safe and which ones put your data at risk?

Out of seven browsers, ChatGPT Atlas, Chrome with Gemini, Claude for Chrome, and Perplexity Comet were found vulnerable. Microsoft Edge with Copilot, Brave Leo, and Firefox AI Mode showed stronger security properties, though Firefox was also the most limited in capability.

Researchers disclosed the findings to all companies involved. Anthropic and Firefox did not respond. Whereas Perplexity and OpenAI declined to act, arguing the researchers lacked a complete end-to-end attack demonstration. Meanwhile, Google, Microsoft, and Brave engaged constructively with the findings.

This follows the recent BioShocking exploit, which also showed how AI browsers can be manipulated by context. Right now, the research suggests AI browsers may still be moving faster than their security can keep up.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Mark Rober’s new CrunchLabs mysteries turn reading into a hands-on STEM adventure
Rober is expanding CrunchLabs with a series of mystery books focus on improving STEM skills with a fun twist.
Book, Publication, Comics

Mark Rober has spent years proving that science and engineering don’t have to feel like homework. His enormously popular videos turn subjects such as physics, robotics, and mechanical engineering into spectacular challenges, ingenious pranks, and machines that kids immediately want to understand.

CrunchLabs has carried that approach into the physical world with its Build Box subscriptions. Now Rober is taking it in another direction: children’s fiction.

Read more
Keychron made 96 blank keys somebody else’s problem
The 10-by-10 macro pad turns an empty grid into a customizable control panel
Computer Hardware, Electronics, Hardware

Keychron has built a 100-key macro pad for anyone who has ever looked at a keyboard and wished none of its buttons had jobs yet. The Keychron C100 8K costs $64.99 and presents a 10-by-10 grid with no letters, numbers, or commands assigned.

Four corner keys are reserved for lighting controls and can’t be remapped, leaving 96 programmable positions. That's still nearly an entire full-size mechanical keyboard devoted to shortcuts, except nobody has decided what any of them should do.

Read more
Samsung is reportedly using Claude to speed up chip design
Samsung engineers are using Claude Code to automate parts of semiconductor verification and software development, with one task reportedly taking two days instead of more than a month.
Claude website open on laptop

Samsung has reportedly turned to AI to speed up one of the slowest and most demanding parts of designing chips. According to a report from Chosun Biz, the company's engineers are using Anthropic's Claude to dramatically accelerate certain tasks, with one project reportedly completed roughly fifteen times faster than usual.

Samsung cut one chip verification task from over a month to two days

Read more