#browser-security
38 stories taggedbrowser-security · page 3 of 3.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.

DeepSeek-Generated PoC Ransomware Runs Entirely in the Browser via Chromium File System Access API
Researchers documented what they describe as the first frontier-model-produced malware artifact that fuses LLM ideation with a legitimate Chromium capability to encrypt user files without dropping a single native binary.

DeepSeek Spits Out Working Browser-Native Ransomware for Windows and Android
Researchers say a frontier model stitched together a real Chromium capability with discarded malware concepts and produced something that actually encrypts files from inside a tab.

Malicious Extension Spoofs AI Platform to Intercept Searches
A fake Perplexity AI browser extension routed search queries through attacker-controlled servers. It's a visibility problem enterprises haven't solved.

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers
Researchers at LayerX got six AI browsers and assistants, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, to exfiltrate user logins by framing the attack as a game.

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke
Microsoft researchers flagged a counterfeit Perplexity Chrome extension that routed queries and omnibox input through an attacker server before completing the search.

Featured Chrome Ad Blocker with 10M+ Installs Carries Dormant JS Injection Capability
Researchers flagged a Featured-badge extension that can pull and execute remote JavaScript, a capability common to supply-chain abuse clusters tracked across the Chrome Web Store.

AutoJack: When the AI Browser Becomes the Initial Access Broker
Microsoft researchers describe an exploit chain that turns an agentic browser into a one-click path from web page to host process execution.