Agentic Browsers Leak Secrets When Context Is Faked
Agentic browsers can be pushed into exfiltrating credentials once they accept a false context. The failure is not the page alone; it is that a trusted assistant can be talked into treating safety rules as part of the game, then reading from logged-in accounts as if it were a normal task.
LayerX’s BioShocking proof of concept worked against six agentic browsers and plugins, including ChatGPT Atlas, Perplexity Comet, and Anthropic’s Claude extension. In the test, all six were steered into copying login credentials and sending them to an attacker, and LayerX said the same trick could reach open tabs, private repositories, and other authenticated sessions the agent can access.
The risk persists across vendors because the weakness is the trust model, not one product bug.