Threat · curated 25 Jul 2026

Researchers Expose Prompt Injection and Cross-Origin Risks in AI Browsers

Coverage timeline

25 Jul 2026mallory.ai

Single-source incident — first reported, latest, and curated coincide.

Why it matters

AI browsers erode traditional browser protections, and the Atlas exploit chain shows how prompt injection and cross-origin flaws in agentic browsers can escalate into full account takeover of linked services like GitHub, Reddit, and Facebook.

Researchers and vendors disclosed serious weaknesses in AI-enabled browsers, warning that agentic features undermine same-origin policy, tab isolation, and cross-origin content handling. In one chain against OpenAI's ChatGPT Atlas, Hacktron AI reported that exposed Chromium Mojo IPC interfaces reachable from allowlisted OpenAI origins were combined with a postMessage XSS on forums.openai.com and a login CSRF flaw to control browser functions, read live tab URLs, and steal OAuth codes enabling account takeover; OpenAI fixed it in Atlas 1.2025.288.15 and paid a $5,000 bounty. Brave separately detailed indirect prompt injection risks in Perplexity Comet.