Updated
Updated · Livescience.com · Jul 24
Study Finds 7 AI Browsers Bypass Security, Exposing User Data
Updated
Updated · Livescience.com · Jul 24

Study Finds 7 AI Browsers Bypass Security, Exposing User Data

3 articles · Updated · Livescience.com · Jul 24

Summary

  • Seven AI browsers tested by researchers could bypass parts of the web’s same-origin policy, letting malicious sites potentially reach data from other tabs, frames or browsing history.
  • The flaw stems from agentic browsers needing broad visibility across pages to summarize content, automate tasks and act on prompts—opening the door to prompt injection and “memory poisoning.”
  • Atlas, Claude for Chrome and Perplexity Comet drew particular concern because stronger capabilities can also mean wider access, while Brave and the AI modes in Edge and Firefox appeared more constrained.
  • Researchers presented the findings at an April 26 workshop in Rio de Janeiro and said the products, many launched only in 2025, still lack a standardized security model.
  • The study argues browser makers are trading security for functionality under competitive pressure, raising the broader question of how to add AI agents without undoing decades of browser hardening.

Insights

Are AI browsers breaking the web’s core safety rule—and exposing your email, banking, and private tabs in the process?
If poisoned memory can persist across sessions, are today’s agentic browsers creating a long-term hidden attack channel?