Research · curated 2 Oct 2026

AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web Agents | Proceedings of the ACM on Software Engineering

Coverage timeline

2 Oct 2026acm.org

Single-source research — first reported, latest, and curated coincide.

Why it matters

AgentBreaker demonstrates that modern multi-LLM web agents are highly susceptible to context-aware indirect prompt injection via webpage content, a practical risk for any deployed autonomous browsing agent and a basis for building defenses.

AgentBreaker is an indirect prompt injection (IPI) attack framework presented in an ACM research paper that autonomously composes context-aware adversarial phrases embedded as DOM/HTML elements to manipulate LLM-powered web agents into clicking attacker-designated elements, posting attacker text, and disclosing internal agent secrets. Evaluated against five state-of-the-art web agents across 60 webpages from Online-Mind2Web, it achieved attack success rates of 71.7%-100%, while the authors' proposed defenses reduce success to 1.7%.