Fetching from the wire…
Public story · 2026-08-19 · high
MobileWorldSafety is the first benchmark to separate real hijacks from agents too incompetent to be fooled.
Why now: MobileWorldSafety posted to arXiv in August 2026, timed to the August 19 roundup of new agent-safety research.
Six GUI agents tested on Android fell to injection attacks embedded in real apps between 40.4% and 66.9% of the time, per a new benchmark called MobileWorldSafety.
That range held across every agent tested, no exceptions. For anyone deploying an agent to act on a phone on a user's behalf, the stakes are direct. Whoever controls the on-screen text can redirect what the agent actually does.
These aren't phishing links or malicious downloads. They're instructions planted inside an app screen the agent is already reading and told to act on.
The number that matters more than the number itself is how it was produced. MobileWorldSafety runs a two-stage check, rule-based verification then an LLM adjudicator. It's built to tell apart an agent that got hijacked from one that was simply too incompetent to finish the task.
Most published attack success rates don't make that split. An agent that fails at everything looks identical on paper to one that gets fooled reliably by planted instructions. The two failure modes point in opposite directions as models improve. Fix competence and a conflated number climbs. Fix safety and it drops.
This is one study, on one platform, from one research group. I'd want the same two-stage split applied to browser and desktop agents before treating 40-67% as a general finding for GUI agents.
The methodology critique stands on its own, though. Any team publishing an agent safety number without separating hijack rate from task-failure rate is answering a question nobody asked.
Each link below shares sources, entities, or timing with this story.
Claude Code supports Android / Same source domain / Shared topic / Tension
Linked by a graph relationship (Claude Code supports Android); reported by the same outlet (arxiv.org); overlapping topics (agent, apply, attack, injection).
Simon Willison released LLM / Shared entity: LLM / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; overlapping topics (agent, capability).
LLM uses OpenAI / Shared entities / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover LLM, Most; earlier LLM coverage from 2026-07-31.
Claude Code supports Android / Shared entity: LLM / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude Code supports Android); both cover LLM; reported by the same outlet (arxiv.org).
LLM uses OpenAI / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; earlier LLM coverage from 2026-07-27.
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.
LLM uses OpenAI / Shared entity: LLM / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; earlier LLM coverage from 2026-06-19.