Researchers say a malicious web page can trick several AI-powered browsers into ignoring safety rules and stealing sensitive data from other sites the user can access. LayerX tested a proof of concept against ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and Anthropic’s Claude Chrome plugin, using a fictional game scenario to push the browser agent into copying secrets from a GitHub repository; OpenAI reportedly fixed the issue in ChatGPT Atlas, while other products remained vulnerable or unresponsive.
Why it matters: People using AI browsers or browser agents could be tricked into letting them exfiltrate passwords or other sensitive information through normal browsing sessions. Vendors need stronger guardrails and user-confirmation checks, and users should limit these tools’ access to sensitive sites and data.
Ionut Arghire
2026.07.02
98% relevant
This is a direct report on the BioShocking attack, adding product-level details on the six tested agentic browsers, the GitHub SSH-credential exfiltration demonstration, and vendor response status including OpenAI's patch, Anthropic's failed patch, and non-responses from several vendors.
Bill Toulas
2026.06.30
100% relevant
This article establishes a distinct new story about the BioShocking prompt-injection technique and the vendor responses across multiple AI browser products, rather than updating a previously tracked single-product AI-agent flaw.
← Back to all stories