Research · curated 30 Jul 2026
Some agentic AI browsers may come with major cybersecurity risks
First reported techxplore.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Agentic browsers with access to a user's credentials, email, and banking can be tricked into leaking cross-origin data, undermining a foundational web security protocol that defenders and users rely on.
University of Washington researchers studied seven agentic AI browsers and found four allow attackers to bypass the same-origin policy, running a successful proof-of-concept attack against ChatGPT Atlas in which a malicious embedding website used prompt injection and the agent's cross-origin access to steal data from another embedded site. Similar attack conditions were identified in Chrome with Gemini, Claude for Chrome, and Perplexity Comet.