Analysis
Indirect Prompt Injection: How It Hijacks Your AI Browser
Publication date unknown · Discovered guard.io
Page published
Publication date unknown · First observed: 8 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Indirect prompt injection turns ordinary web content into a hijack vector for AI browser assistants, exposing user session data and actions without any user interaction.
Guardio's research team explains indirect prompt injection (IPI), in which hidden instructions embedded in webpages, documents, or emails are processed by AI browser assistants (such as Microsoft Copilot and browser-integrated ChatGPT) and acted upon as legitimate commands, potentially leaking session data, endorsing phishing sites, or destroying files. The article is an explainer that references OWASP's ranking of prompt injection as the #1 LLM application risk and notes researchers are finding IPI on live sites.