A University of Washington study looked at seven agentic web browsers released by companies in the last year. The researchers tested how these browsers let AI agents open tabs, research options and perform tasks for users.
They found that four browsers provided ways for attackers to bypass the same-origin policy, a rule that keeps different websites from accessing each other's data. In a proof-of-concept test, a website embedded another site and stole information, for example an ad taking sensitive data from a user's email.
The study explains two main risks. One is prompt injection, where hidden instructions trick an agent into moving or revealing data. The other is memory poisoning, where agents mix stored information from different sites. Browsers that gave agents fewer permissions were generally safer, and the researchers told companies about the problems.
Difficult words
- agentic — software that acts and makes choices for users
- same-origin policy — rule that stops different websites sharing data
- embed — to put one thing inside another, for example a siteembedded
- prompt injection — hidden instruction that makes an agent reveal data
- memory poisoning — mixing stored information from different sources
- permission — allowed access or rights to use a featurepermissions
Tip: hover, focus or tap highlighted words in the article to see quick definitions while you read or listen.
Discussion questions
- Would you use a browser that lets AI agents open tabs? Why or why not?
- How could companies make browsers safer from these risks?
Related articles
Sportellino: a multilingual chatbot for migrants in Italy
A multilingual chatbot called Sportellino launched to help migrants in Italy find public services and practical guidance. It is free, anonymous and available via messaging apps; its information is based on official sources and experts.