HomeSecurityNew prompt injection attack against AI browsers and browser assistants

New prompt injection attack against AI browsers and browser assistants

Security researchers have unveiled a new indirect prompt injection attack against AI browsers and AI browser assistantsthat could lead to phishing, sensitive data extraction, credential theft , or malware download. The attack, dubbed HashJack, relies on malicious prompts added to URLs after the pound sign (#), also known as a named anchor or URL fragment.

prompt injection AI browsers

“ HashJack is the first known indirect prompt injection technique that can weaponize any legitimate website to manipulate AI browser assistants ,” researchers from Cato Networks reported . “ As a result, AI browsers — including Comet (Perplexity), Copilot for Edge (Microsoft), and Gemini for Chrome (Google) — can be used to enable a wide range of malicious attacks .”

See also: New browser security report reveals emerging threats to businesses

Client-side attack

The nature of the attack (client side) shows that traditional network defenses, such as IPS/IDS and network firewalls, are not effective. Server logs do not record the part of URLs after the # because it is never sent to the server, and browser defenses such as Content Security Policy (CSP) are not triggered because nothing on the page changes.

HashJack: A social engineering attack?

HashJack is essentially a social engineering attack because it relies on tricking users into clicking on specially crafted URLs within emails, chats, websites, or documents. However, this attack can be particularly credible because it points to legitimate websites. For example, imagine a fake email claiming to be from a bank and informing customers of suspicious activity in their accounts. Hovering over the link, included in the email, shows that it leads to the bank’s real website, HTTPS and all, but it’s a long link and somewhere in it there’s a # symbol followed by a prompt for the AI ​​assistant.

New prompt injection attack against AI browsers and browser assistants

Many users are likely to trust such a message since it points to the real bank website and because long links with many parameters and paths are not uncommon. But the prompt following the # symbol will cause the AI ​​browser assistant to provide instructions to the user, such as calling a phone number or WhatsApp link controlled by the attacker for further customer support regarding the alleged situation.

See also: AI browsers abused by malicious AI sidebar extensions

In another scenario, a prompt included in the link can tell an AI browser, acting as an agent, to get information about the user's account, transaction history, phone number , etc. from the opened bank website and add them as parameters to a request to the attacker's server.

Other attacks could include prompting the AI ​​assistant to display false information that would mislead the user: fake investment advice promoting a specific stock, fabricated news, dangerous medical advice such as wrong dosages for medications, malicious instructions that could open a backdoor on the computer, instructions for re-certification that include a link to a phishing website, a link to download malware, etc.

URL fragments cannot modify the content of the page. They are only used to navigate within the page using code that is already there, so they are usually harmless. However, it has now been shown that they can be used to modify the output of in-browser AI assistants or agentic browsers. “This discovery is particularly dangerous because it weaponizes legitimate websites through their URLs,” the researchers said. “Users see a trusted website, trust their AI browser, and in turn trust the output of the AI ​​assistant, making the probability of success much higher than traditional phishing attacks.”

See also: DoorDash: AI browsers pose a big threat to Amazon

New prompt injection attack against AI browsers and browser assistants

How were different AI browsers affected?

The impact varied across the AI ​​assistants tested. For example, while prompt injections were able to affect text output in all products tested, inserting malicious links proved more difficult in Gemini Assistant for Chrome and Edge with Microsoft Copilot.

Perplexity's Comet , which is an agentic browser and does more than just have a built-in AI assistant, was the most vulnerable because it could also serve attacker URLs in the background, with context information attached as parameters.

Microsoft and Perplexity have developed fixes, but Google has not considered the HashJack technique a vulnerability because it sees this as part of the intended behavior. It is worth noting that Cato also tested Claude for Chrome and OpenAI's Operator browser, but the HashJack technique did not work on them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS