Security researchers keep finding ways to trick AI browsers into leaking your one-time passcodes

Started by Bright Hermit, Jul 19, 2026, 01:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Security researchers keep finding ways to trick AI browsers into leaking your one-time passcodes   Views(Read 37 times)
Active members in this topic:
Bright Hermit(1)

Bright Hermit

AI powered browsers like Perplexity's Comet, OpenAI's Atlas, and Google's Gemini integration in Chrome promise to book appointments, fill shopping carts, and summarize your inbox on your behalf. That same power is exactly what makes them vulnerable to prompt injection, hidden instructions buried inside a web page, email or document that get executed as if the actual user had typed them, and both OpenAI and the UK's National Cyber Security Centre have said this risk likely cannot be fully solved, only mitigated

Brave's security team demonstrated exactly how bad this can get with Perplexity Comet. When a user simply asked Comet to summarize a Reddit page, hidden instructions embedded inside a Reddit spoiler tag, invisible to the human eye but readable by the AI, caused the browser to autonomously fetch a one time passcode from the user's email and a stored account address, all without the user ever asking for that specifically. There was no memory corruption or traditional exploit involved, the browser simply followed instructions it had no way to distinguish from the user's own legitimate request

A separate vulnerability tracked as CVE-2026-0628, found by Palo Alto Networks' Unit 42 in Chrome's Gemini Live side panel, let a low privilege browser extension inject code into the AI panel and inherit its elevated permissions, including local file access, screenshots, and control over the camera and microphone. Google patched the flaw in January before the research was publicly disclosed, but the underlying pattern is the same one security researchers keep finding across every major AI browser, giving an AI agent broad, logged in access to your accounts and files necessarily creates a much larger attack surface than a traditional browser that just displays pages

The researchers' practical advice is consistent across every writeup, treat AI browser agents the way you'd treat a new employee with limited trust rather than an extension of yourself, limit what accounts and data each agent can actually touch, avoid keeping your most sensitive logins active in a browser tab an AI agent has access to, and require explicit confirmation before letting any agent complete a sensitive action like a purchase or a password reset. None of these mitigations eliminate the underlying risk, they just shrink how much damage a single successful prompt injection can actually do

Save money on everyday spending Free cashback on thousands of retailers
View offer