Research · curated 9 Aug 2026
Agentic anarchy: Why using AI browsers just isn't worth the risk | news | SC Media
First reported scworld.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI browsers with local file and account access turn indirect prompt injection from untrusted web content into full account and system compromise, showing that agentic browsing broadly expands the attack surface for defenders.
At Black Hat 2026, Zenity researchers Michael Bargury and Stav Cohen demonstrated prompt-injection ('persuasion') attacks against AI browsers including Perplexity Comet, Microsoft Edge with Copilot, Chrome with Gemini, the Anthropic Claude extension, and OpenAI's Atlas. Injections embedded in calendar invites, emails, and social posts led agents to take over a PC in seconds, steal 1Password credentials and recovery keys, send phishing email, exfiltrate files, delete AWS instances, and expose private GitHub repos; Perplexity has since fixed the local-file flaw.