Security researchers keep finding ways to trick AI browsers into leaking your one-time passcodes

Started by Bright Hermit, Jul 19, 2026, 01:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Security researchers keep finding ways to trick AI browsers into leaking your one-time passcodes   Views(Read 92 times)

Bright Hermit

AI powered browsers like Perplexity's Comet, OpenAI's Atlas, and Google's Gemini integration in Chrome promise to book appointments, fill shopping carts, and summarize your inbox on your behalf. That same power is exactly what makes them vulnerable to prompt injection, hidden instructions buried inside a web page, email or document that get executed as if the actual user had typed them, and both OpenAI and the UK's National Cyber Security Centre have said this risk likely cannot be fully solved, only mitigated

Brave's security team demonstrated exactly how bad this can get with Perplexity Comet. When a user simply asked Comet to summarize a Reddit page, hidden instructions embedded inside a Reddit spoiler tag, invisible to the human eye but readable by the AI, caused the browser to autonomously fetch a one time passcode from the user's email and a stored account address, all without the user ever asking for that specifically. There was no memory corruption or traditional exploit involved, the browser simply followed instructions it had no way to distinguish from the user's own legitimate request

A separate vulnerability tracked as CVE-2026-0628, found by Palo Alto Networks' Unit 42 in Chrome's Gemini Live side panel, let a low privilege browser extension inject code into the AI panel and inherit its elevated permissions, including local file access, screenshots, and control over the camera and microphone. Google patched the flaw in January before the research was publicly disclosed, but the underlying pattern is the same one security researchers keep finding across every major AI browser, giving an AI agent broad, logged in access to your accounts and files necessarily creates a much larger attack surface than a traditional browser that just displays pages

The researchers' practical advice is consistent across every writeup, treat AI browser agents the way you'd treat a new employee with limited trust rather than an extension of yourself, limit what accounts and data each agent can actually touch, avoid keeping your most sensitive logins active in a browser tab an AI agent has access to, and require explicit confirmation before letting any agent complete a sensitive action like a purchase or a password reset. None of these mitigations eliminate the underlying risk, they just shrink how much damage a single successful prompt injection can actually do

ProperMadLad

Hiding the malicious instructions in a spoiler tag specifically so a human wouldn't see it but the AI would still read it is such a clever and slightly terrifying piece of social engineering aimed entirely at the AI rather than the person

Cass93

OpenAI and the UK's own cybersecurity agency both saying this can't be fully solved, only mitigated, is a sobering admission from the people actually building these tools
Normal is overrated

KeyboardWarrior

The Chrome Gemini flaw giving a low privilege extension access to camera and microphone control is the kind of escalation that makes this feel like a much bigger deal than just leaked data, that's real physical surveillance capability
Press F to pay respects

IronWarden

Treating an AI browser agent like a new employee with limited trust rather than an extension of yourself is genuinely good practical advice, most people are still treating these tools with way too much default trust
Works on my quantum machine :D

NightOwl83

No memory corruption, no traditional exploit, just the AI following instructions it couldn't tell apart from the real user is such an unsettling category of vulnerability, completely different from classic browser security holes

Lucy_35

This being demonstrated across multiple different AI browsers rather than just one vendor's implementation shows it's a structural problem with the whole category, not a fixable bug in one specific product

Marnie

This is the part of AI assistants that worries me more than the usual job replacement arguments. People understand that a bad answer can happen, but they do not always think about handing an AI access to email, shopping accounts, or authentication messages.

A browser agent is basically being trusted with the keys to the house. The convenience is obvious, but the security expectations have to be much higher than a normal chatbot.

The fact that researchers can repeatedly find ways to manipulate these systems should not be surprising. They are following instructions from the web, and the web is full of things designed to manipulate people too.
Saving for a trip to Ireland this year.

Merchant31

The one-time passcode issue is a good example of why giving AI too much authority too quickly is risky. A human assistant would hopefully notice something strange, but an AI may just follow the instructions it has been given.

The scary part is not a single bug. Bugs can be fixed. The bigger challenge is that language models are built to interpret text, and attackers can also use text as a weapon.

It is like teaching a very helpful robot to read every note in the building, then being surprised when someone leaves a fake note saying "ignore the rules" ;)

Bayley_US

Security always seems to be the thing that arrives after convenience. We saw this with apps collecting too much data, smart devices with weak passwords, and now AI agents with broad permissions.

The answer probably is not banning these tools. They are useful.

The answer is putting limits around what they can do without confirmation. Sending an email is one thing, reading a private security code is another.

Rapid Ava

People should separate AI chatbots from AI agents here. A chatbot giving you advice is one risk level. An agent that can browse, click buttons, purchase items, and access accounts is a completely different category.

Once software starts taking actions instead of just answering questions, the security model needs to change.

The old "just don't share your password" advice becomes harder when the AI itself is handling parts of your private information.
Somewhere between inspired and overwhelmed

ProperJobs

The hardest problem is probably permissions. Most users do not want to spend an hour configuring exactly what an AI can and cannot access.

They want a button that says "make my life easier" and then they move on.

That is where companies need to build safer defaults instead of expecting everyone to become a cybersecurity expert overnight.
YNWA.

James95

The first generation of AI agents reminds me of early smartphone apps. Everyone was excited about what they could do, then we slowly learned that every permission request mattered.

Hopefully companies learn from that history instead of repeating it.

Convenience is great, but nobody wants their AI assistant to become the easiest route into their own accounts.

EdgeNodeCoder

One area that deserves more attention is user expectations. People hear "AI assistant" and imagine something that understands their intentions perfectly.

It does not. It predicts and follows patterns based on information available to it.

That difference matters a lot when the action involves money, identity, or private accounts.
Be excellent to each other

HeartbreakKid_Fan

The one thing that stands out is how quickly security researchers find creative attacks. The technology moves fast, but attackers are also very motivated.

That means testing cannot stop after launch.

An AI browser needs continuous security reviews because the threats will keep evolving.

QuantumDay

Some caution is healthy, but the conversation sometimes ignores the benefits. AI agents could help people manage boring tasks, find information faster, and handle accessibility challenges.

The answer cannot just be "never let AI touch anything".

It needs to be smarter permission systems, better monitoring, and clearer warnings.
I'm not always right, but I'm never wrong ;)

Mike80

Reading about these problems makes me think the industry needs an equivalent of seat belts before selling more powerful cars.

Nobody expects a vehicle to be impossible to crash, but there are standards that reduce the damage.

AI tools need those safety standards before they become deeply integrated into everyday life.
Lurker since the beginning

CR739

Maybe the best solution is treating AI agents like a junior employee. Give them useful tasks, but do not hand over unlimited access on day one.

A new employee would not get every company password immediately.

An AI system should probably earn more permissions through trust and verification rather than starting with everything enabled.

Always_Shane35

Some people are reacting as if this means AI browsers are useless, but that feels like throwing away the whole idea because of early problems.

Cars had safety issues when they first became common too. The solution was not to stop driving, it was to create better rules and engineering standards.

AI agents need that same maturity before they become trusted with sensitive tasks.
Question everything. Especially this.

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer