AI browser makers tout seamless automation, but new research reveals a dangerous vulnerability. A website can lull an AI browser into a false reality where its guardrails cease to function, allowing attackers to extract private repository code or credentials from password managers.
This attack highlights the inadequacy of reactive safety measures, which treat symptoms rather than root causes. The finding underscores the inherent risks of blurring the line between browsing and allowing LLMs to take sensitive actions.
Comments