Threat · curated 30 Jun 2026
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
First reported thehackernews.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
AI browsers acting on behalf of users can be manipulated into exfiltrating login credentials, exposing a serious risk to anyone using agentic browsing assistants.
LayerX disclosed a technique called BioShocking that convinces AI browsers they are playing a game, tricking them into copying a user's credentials and sending them to an attacker. Six AI browsers and assistants were affected, including OpenAI's ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude browser extension.