Researchers at Cato Networks have identified a new attack technique called HashJack, which leverages the fragment portion of URLs (the section after the # symbol) to hide malicious prompts. This method specifically targets AI browser assistants such as Copilot in Edge, Gemini in Chrome, and Comet from Perplexity AI. When users interact with these AI-powered browsers, the hidden instructions in the URL fragment are processed by the large language model, potentially leading to outcomes like data exfiltration, phishing, misinformation, malware guidance, or even harmful medical advice. Traditional network and server-side defenses are unable to detect these attacks because URL fragments are never transmitted beyond the client, making legitimate websites unwitting vectors for exploitation.
The HashJack attack is a form of indirect prompt injection, where attackers craft links to trusted sites with appended malicious instructions after the # symbol. Unsuspecting users who click these links and then use their AI browser assistant may trigger the hidden prompts, which can manipulate the assistant to perform harmful actions or leak sensitive data. The risk is heightened in agentic AI browsers, where the assistant may autonomously send user data to attacker-controlled endpoints. Security researchers warn that this technique can weaponize any legitimate website, underscoring the urgent need for improved defenses in AI browser architectures against prompt injection threats.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple outlets reported Cato's public disclosure of HashJack, describing how URL fragments on legitimate sites could be weaponized to trigger phishing, misinformation, malware delivery, or data exfiltration through AI browser assistants. The disclosure highlighted that traditional network and server-side defenses are ineffective because the malicious content remains client-side.
Following disclosure, Microsoft and Perplexity implemented fixes to address HashJack-related abuse in Copilot for Edge and Comet. Reports indicate Google did not issue a fix and instead treated the behavior as intended.
Cato notified vendors about the HashJack issue after validating the technique against multiple AI browser assistants. Google was informed but classified the behavior as low severity or intended behavior rather than a security vulnerability.
Cato CTRL researchers identified a new indirect prompt injection method, dubbed HashJack, that hides malicious instructions in URL fragments to manipulate AI browser assistants. Testing showed successful exploitation against Perplexity Comet, Microsoft Copilot for Edge, and Google Gemini for Chrome, while Claude for Chrome and OpenAI Atlas/Operator were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.