Research · curated 30 Jul 2026

Some agentic AI browsers may come with major cybersecurity risks

Coverage timeline

3 Jul 2026techxplore.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Agentic browsers with access to a user's credentials, email, and banking can be tricked into leaking cross-origin data, undermining a foundational web security protocol that defenders and users rely on.

University of Washington researchers studied seven agentic AI browsers and found four allow attackers to bypass the same-origin policy, running a successful proof-of-concept attack against ChatGPT Atlas in which a malicious embedding website used prompt injection and the agent's cross-origin access to steal data from another embedded site. Similar attack conditions were identified in Chrome with Gemini, Claude for Chrome, and Perplexity Comet.