AI browser makers promote convenience but downplay the risks of blending web browsing with direct LLM commands. Current guardrails are reactive and treat symptoms rather than root causes.
New research demonstrates that a website can lull an AI browser into an alternate reality where its safety rules no longer apply, giving attackers free rein to extract private code or credentials from password managers. The work underscores fundamental security flaws in the AI browser model.
Comments