Research · curated 2 Oct 2026
AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web Agents | Proceedings of the ACM on Software Engineering
First reported acm.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AgentBreaker demonstrates that modern multi-LLM web agents are highly susceptible to context-aware indirect prompt injection via webpage content, a practical risk for any deployed autonomous browsing agent and a basis for building defenses.
AgentBreaker is an indirect prompt injection (IPI) attack framework presented in an ACM research paper that autonomously composes context-aware adversarial phrases embedded as DOM/HTML elements to manipulate LLM-powered web agents into clicking attacker-designated elements, posting attacker text, and disclosing internal agent secrets. Evaluated against five state-of-the-art web agents across 60 webpages from Online-Mind2Web, it achieved attack success rates of 71.7%-100%, while the authors' proposed defenses reduce success to 1.7%.