Analysis · curated 2 Sep 2026
Zero-Click Prompt Injection: AI Web Browsing Exploits (2026)
First reported codesecai.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Zero-click prompt injection lets attackers weaponize the web-browsing capabilities of widely deployed AI assistants to exfiltrate private conversational data without any user interaction, making it a key threat class for defenders securing RAG systems.
A guide on codesecai.com explains "zero-click prompt injection" against AI web-browsing agents, where adversaries embed invisible instructions in public HTML/CSS/Markdown (zero-opacity text, micro-fonts, comments, image pingbacks) that headless browser extractors ingest. It describes how injected Markdown image tags trigger outbound requests that silently exfiltrate user chat history to attacker-controlled servers on platforms like Perplexity, ChatGPT Search, and Microsoft Copilot.