• WWW.LIVESCIENCE.COM
    AI web browsers 'aren't ready for the public,' scientists warn as they highlight massive security red flags
    Researchers have discovered a security flaw in AI web browsers that could result in users having their data exposed by malicious websites.Browsers equipped with AI agents, such as ChatGPT's Atlas, are like ordinary internet browsers but with additional chatbot functionality baked into the software. Using AI, agentic browsers can summarize websites, search for specific information, and even automate repetitive tasks. For example, somebody may use an AI browser to make a purchase whereas they would have to browse a webstore for the item and then make the payment if they used a conventional browser. Many agentic browsers have only been released in 2025, and they're already rising in popularity. Scientists, however, have warned in a new study that many popular AI browsers bypass an important security measure that keeps their data private. They presented their findings April 26 at the Agents in the Wild Workshop in Rio de Janeiro, Brazil."Browser agents aren't ready for the public," said co-author of the study David Kohlbrenner, an assistant professor of computer science and engineering at the University of Washington, in a statement. "Even if youre a relatively savvy user, if these agents have access to a browser that contains your credentials your email, your bank account, whatever it is you should not trust that these systems are ready to truly protect your information. They may get there in time, but they're not there yet."Bypassing embedded securityConventional internet browsers use a security protocol called the "same-origin policy," which ensures that multiple websites a user is visiting at the same time do not interact with each other. This is to stop potentially malicious online content from spilling over into other sites. For example, if a user had a bank's website open in one tab with a webpage containing malicious code in another, the same-origin policy would prevent these two sites from interacting.However, AI browsers require full access to all the web content available to the user, which could include cross-origin iframes code shared across multiple websites, such as online advertisements or require cross-origin visibility so they can access information from multiple websites. An AI browser essentially has the same overview as a user.Although internet browser security has been hardened through decades of research, the security for AI browsers remains in its infancy. One major risk, for instance, is "prompt injection," whereby an AI agent is tricked into misinterpreting data embedded on a malicious website as an instruction they need to carry out. In their study, the researchers offered an example of an AI browser visiting an otherwise "safe" website, with malicious code embedded within that contained a hidden instruction for the agentic browser to automatically share the user's personal details.Roesner also highlighted "memory poisoning" as a massive risk, in which AI agents store information they've processed in their memory for future use, making the content vulnerable to attack. He added in the statement: "We found that some of these agents would mingle information from different origins, likely because they were revising and compressing their memory." The better the browser, the riskier it isThe key focus in this research was to assess how current AI browsers interact with the same-origin policy and what the security implications could be. The researchers examined seven browsers including Atlas, Claude for Chrome, Brave Leo AI, Chrome with Gemini, Microsoft Edge with CoPilot, Firefox AI Mode and Perplexity Comet with test sites and prompts, allowing them to study how each behaved. They focused on the information an agent could access from same-origin and cross-origin webpages, the actions each agentic browser can undertake on the web, and the agents chat context and history.There is no consistency among AI browsers in how they operate, the researchers found, which they suggest could be due to the lack of standardization in how AI browsers interact with browser security.Several AI browsers could freely access cross-origin frame content, while others restrict access. Likewise, some agentic browsers could simultaneously access multiple tabs, but most require permission from the user. Similarly, some agents could take actions directly on a page in response to instructions on a webpage, but others are unable to take any actions at all.Related storiesAI hallucinations work both ways, study shows using chatbots can amplify and reinforce our own delusionsThere are 32 different ways AI can go rogue, scientists say from hallucinating answers to a complete misalignment with humanityAI may accelerate scientific progress but here's why it can't replace human scientistsThe researchers recommended that users be careful in choosing which AI browser they install, as a standardized security model has not been developed. They are particularly cautious about Claude for Chrome, well-known for its strong capabilities, as well as Atlas and Comet, which have similarly strong functionality. The researchers identified Brave, as well as the agentic versions of Edge and Firefox, as having stronger security due to their limited agentic features.According to the study, AI browsers have not yet established the right trade-offs between functionality and security. Currently, the more functional a browser is, the less secure it becomes. "We've had some really good exchanges with folks at Google, Microsoft and Brave," Roesner said. "Companies are pushing out these browsers because theyre under competitive pressure. But how to make them safe is still an open question. After 30 years of building up this same-origin policy, this is a big step back for browser security."Looking to the future, the researchers questioned how AI agents can be integrated into browsers in ways that provide rich functionality without undermining the browser's security and potentially exposing sensitive information.
    0 Comments 0 Shares 11 Views
  • WWW.UNIVERSETODAY.COM
    Mars Express Captures 'Metallic' Waves Rolling Across an Ancient Martian Crater
    When we think of Mars as the Red Planet, the image that comes to mind is just that - a lot of red. That comes from the oxidization of the dust and rocks that cover the planet's surface, but there are some instances where the Red Planet still has a few visual tricks up its sleeve. One such trick was recently captured by the European Space Agencys venerable Mars Express orbiter, which captured what seems to be a set of metallic waves inside a giant impact basin. But on closer inspection, it becomes clear they arent liquid metal or some sort of alien architecture, but a manifestation of Mars complex environment.
    0 Comments 0 Shares 14 Views
  • 0 Comments 0 Shares 3 Views
  • WWW.IFLSCIENCE.COM
    Watch As A Seizure Speeds Through A Brain In Fascinating, First-Of-Its-Kind Video
    Clever microscopy techniques allowed scientists to watch a seizure spread through the brain in real time.
    0 Comments 0 Shares 7 Views
  • 0 Comments 0 Shares 14 Views
  • 0 Comments 0 Shares 7 Views
  • WWW.THEKITCHN.COM
    Key Lime Margarita
    The graham cracker rim is a must.READ MORE...
    0 Comments 0 Shares 15 Views
  • WWW.BGR.COM
    Are Electronics In Duty-Free Stores Actually Much Cheaper?
    Duty-free pricing sounds appealing when you're shopping for a phone, laptop, or camera, but several costs determine whether you're getting a good deal.
    0 Comments 0 Shares 3 Views
  • TECHCRUNCH.COM
    As US weighs response to Chinese AI, industry urges against broad open-weight restrictions
    AI companies including Nvidia and Mistral urge policymakers to avoid broad restrictions on open-weight AI models as Washington debates responses to Chinese AI and alleged model distillation.
    0 Comments 0 Shares 8 Views
  • TECHCRUNCH.COM
    Rivian sues the US government for full refund of Trump tariffs
    The carmaker has said it's owed a refund in the "tens of millions of dollars."
    0 Comments 0 Shares 14 Views