No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Your AI Browser May Be Vulnerable to ‘Prompt Injection’ Attacks

September 9, 2025
in Protection
0
Your AI Browser May Be Vulnerable to 'Prompt Injection' Attacks



Did you know you can customize Google to filter out garbage? Take these steps for better search results, including adding Lifehacker as a preferred source for tech news.


AI continues to take over more and more of our day-to-day activities: Anthropic recently announced a Chrome extension that allows Claude AI to see browser activity and run actions on behalf of users, while Perplexity’s Comet is an AI-powered browser that the company calls both a “personal assistant” and a “thinking partner.”

Agentic browsers may be able to do a lot of things for you, such as scheduling meetings, replying to emails, and ordering DoorDash, but handing all of this control (and personal information) over to AI comes with potential security risks. One of these is a prompt injection attack, which allows hackers to trick the AI into following their instructions instead of yours.

What is a prompt injection attack?

A prompt injection attack is when hackers disguise malicious inputs to AI as legitimate ones, so generative models are tricked into divulging sensitive data or taking harmful action.

As IBM describes, large-language models (LLMs) are given sets of instructions—system prompts—for how to handle user inputs. These two elements are combined into a single command, both written in natural language, which means that the LLM cannot separate which part of the command is the system prompt and which comes from the user. If threat actors create an input that bears enough resemblance to a system prompt, it could supersede the legitimate developer instructions and force the LLM to follow the fake ones.

In practice, this may involve hiding malicious prompts on a webpage the LLM is likely to read in order to carry out an action. The content, which could be plain text or embedded in an image or PDF, may look harmless or be invisible to users (employing white text on a white background, for example). Hackers don’t need code to carry out a prompt injection attack—just the right words in the right place.

How prompt injection compromises agentic browsers

While browsers with AI integration still require some manual input to complete tasks, agentic browsers act more like autonomous assistants that can follow entire workflows without user approval. That means that there’s no safeguard of human review before AI potentially shares your information, runs a malicious program, or spends money on a fraudulent purchase.


What do you think so far?

An example from Malwarebytes Labs: You ask your agentic browser to find and book a cheap flight for your next vacation. If it has all of your passenger and payment information available (because you’ve provided it), AI can complete this request without any additional action from you. But if the cheapest flight is found on a malicious website set up for this purpose, the browser could hand your credit card number and other sensitive data directly to the scammers.

A recent report from researchers at Brave (which has its own AI assistant) outlines particular concern about Perplexity’s Comet, with tests showing that the agentic browser is vulnerable to prompt injection attacks and hasn’t yet fixed the issue. Anthropic, for its part, has acknowledged its vulnerabilities and notes that it is working on safeguards to minimize them.

How to safely use agentic browsers

Mitigating prompt injection attack risks falls largely on the developers of agentic browsers rather than the user, with security experts recommending higher standards for user interaction and distinguishing between a user’s request and other content consumed to carry out an task.

That said, while Perplexity and Anthropic and others address these issues on their end, you can put guardrails in place against prompt injection, such as limiting the data and accounts your agentic browser can access and requiring manual review for high-stakes tasks, such as authorizing payments. Malwarebytes Labs also recommends enabling multi-factor authentication on all accounts connected to agentic browsers, regularly reviewing account and browser activity, and keeping software updated to ensure security flaws are patched in a timely manner.



Editorial Team

Editorial Team

Related Posts

Apple Basically Ignored AI at Today’s iPhone Event
Protection

Apple Basically Ignored AI at Today’s iPhone Event

September 10, 2025
Some iPhone Users Are Getting Another Year of Free Satellite Features
Protection

Some iPhone Users Are Getting Another Year of Free Satellite Features

September 10, 2025
The Base Model iPhone 17 Pro Costs More Than Ever
Protection

The Base Model iPhone 17 Pro Costs More Than Ever

September 9, 2025
Whistleblowers Claim Meta Suppressed Research on Kids' Safety in VR
Protection

Whistleblowers Claim Meta Suppressed Research on Kids’ Safety in VR

September 9, 2025
This Is the Minimum Amount of Training Necessary to Run a Marathon
Protection

This Is the Minimum Amount of Training Necessary to Run a Marathon

September 9, 2025
If You Have a Mini-LED TV, You Need to Enable This Setting
Protection

If You Have a Mini-LED TV, You Need to Enable This Setting

September 8, 2025
Load More
Next Post
Client Challenge

Client Challenge

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Private debt managers expect industry-wide consolidation in 5 years

    0 shares
    Share 0 Tweet 0
  • Crypto-native risk management tactics applied to global currencies

    0 shares
    Share 0 Tweet 0
  • Private Suites in LAX: What to Know

    0 shares
    Share 0 Tweet 0
  • 4imprint Group shares dive following tariff concerns

    0 shares
    Share 0 Tweet 0

Latest News

Most Crypto Tokens Aren’t Securities, Pitches Unified Rulebook

Most Crypto Tokens Aren’t Securities, Pitches Unified Rulebook

September 10, 2025
0

US Securities and Exchange Commission (SEC) Chair Paul Atkins said that “most crypto tokens are not securities,” while outlining a...

The number of motorists blatantly breaking a major rule around parking has become a 'significant problem' across Britain, according to a new report. In a huge poll of almost 15,000 drivers, 51 per cent said illegal parking on double yellow lines has become a scourge where they live. The nationwide poll revealed a growing frustration with motorists who flout parking regulations - particularly in busy urban areas where visibility, access, and safety are paramount.

Report: Parking on double yellow lines becomes ‘significant problem’ in UK

September 10, 2025
0

The number of motorists blatantly breaking a major rule around parking has become a 'significant problem' across Britain, according to...

Client Challenge

Client Challenge

September 10, 2025
0

Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required part of this site couldn’t...

Apple Basically Ignored AI at Today’s iPhone Event

Apple Basically Ignored AI at Today’s iPhone Event

September 10, 2025
0

Apple’s “Awe Dropping” iPhone event today went big on hardware, debuting new AirPods Pro and Apple Watch models, as well...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.