Analysis · curated 2 Sep 2026

Zero-Click Prompt Injection: AI Web Browsing Exploits (2026)

Coverage timeline

17 Aug 2026codesecai.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Zero-click prompt injection lets attackers weaponize the web-browsing capabilities of widely deployed AI assistants to exfiltrate private conversational data without any user interaction, making it a key threat class for defenders securing RAG systems.

A guide on codesecai.com explains "zero-click prompt injection" against AI web-browsing agents, where adversaries embed invisible instructions in public HTML/CSS/Markdown (zero-opacity text, micro-fonts, comments, image pingbacks) that headless browser extractors ingest. It describes how injected Markdown image tags trigger outbound requests that silently exfiltrate user chat history to attacker-controlled servers on platforms like Perplexity, ChatGPT Search, and Microsoft Copilot.