Every AI Browser Tested at Black Hat Fell to Prompt Injection — Brave Researcher Says There Is No Clean Fix
In his Black Hat USA 2026 briefing 'Attacking and Defending AI Browsers,' Brave Software security engineer Artem Chaikin said every browser he analyzed proved vulnerable to indirect prompt injection, demonstrating live against Opera's AI browser, Perplexity Comet, and ChatGPT Atlas. The root cause is structural: agents cannot distinguish ordinary page content from hidden instructions embedded in an email, shared document, calendar invite or webpage, which yields data exfiltration and account takeover. Chaikin's conclusion is that guardrails are improving but the threat class is not going away — meaning agentic browsing should be treated as an untrusted-input problem, not a model-alignment one.
Source
↳ Follow the thread