Researchers and security outlets reported multiple indirect prompt injection weaknesses affecting AI-driven browsing and assistant features, showing how hidden instructions embedded in untrusted web content can manipulate model behavior and steer users into credential theft or data exposure. Cato Networks disclosed WebPromptTrap in BrowserOS, where malicious webpage content abused Agent Chat Mode summarization to insert a convincing call to action and attacker-selected link; in the proof of concept, victims could be pushed into a GitHub authorization flow that exposed access tokens and repository access. Cato said the issue affected BrowserOS 0.30.0 and earlier, was identified in 0.29.0, and was fixed in 0.32.0 after responsible disclosure.
Separate reporting described similar risks in OpenAI's ChatGPT Atlas browser and in Microsoft Copilot, underscoring that the problem extends beyond a single product. LayerX said Atlas could be fed malicious instructions through web content in a "tainted memories" attack, while Axios, TechSpot, and commentary from OpenAI CISO Dane Stuckey highlighted broader security and privacy concerns around prompt injection in AI browsers. Varonis also detailed Reprompt, a single-click Copilot attack that could silently exfiltrate personal data. Together, the disclosures show that AI systems that summarize pages, retain context, or act on behalf of users can be turned into phishing and data-theft intermediaries unless untrusted content is strictly isolated from model instructions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
SafeBreach disclosed an indirect prompt injection technique affecting Google Gemini's notification summarization and voice assistant features, showing how hidden instructions in muted hyperlinks or invisible foreign-language text could misrepresent messages and potentially trigger unauthorized actions. The researchers said Google was notified through responsible disclosure and deployed content-classifier updates; the article said there was no evidence of in-the-wild exploitation.
Permiso published research on 'ChatGPhish,' a browser-based prompt injection technique in which attacker-controlled webpage text influences ChatGPT's page summarization output and causes phishing links, QR codes, spoofed alerts, and remote image fetches to appear inside the trusted ChatGPT interface. The researchers said they reported the issue to OpenAI via Bugcrowd in late April and early May 2026 before publishing their findings.
Cato published details of WebPromptTrap, including a proof of concept showing how a manipulated AI-generated summary could steer a victim into a malicious GitHub authorization flow that yields access tokens and repository access. The researchers warned the same attack pattern could be adapted to other enterprise roles and SaaS platforms such as ERP, HR, payroll, CRM, and service management systems.
After responsible disclosure from Cato, the BrowserOS team remediated the WebPromptTrap issue in BrowserOS 0.32.0. Cato said the vulnerability affected BrowserOS 0.30.0 and earlier.
Cato researchers identified an indirect prompt injection issue in BrowserOS while testing version 0.29.0. The flaw abused Agent Chat Mode page summarization by embedding hidden instructions in untrusted webpage content.
Brave published research describing 'unseeable prompt injections in screenshots' affecting its Comet AI browser and possibly other AI browsers. The disclosure introduced a distinct prompt-injection technique using screenshot content rather than hidden webpage text.
A reference published on 2025-02-17 documented prompt injection exploit scenarios and defensive considerations for ChatGPT Operator. This is a distinct earlier development in the broader prompt-injection story, separate from Cato's later BrowserOS WebPromptTrap findings.
A reference published on 2024-08-20 documented how indirect prompt injection could be used to exfiltrate data from Slack AI. The disclosure added another concrete example of prompt-injection abuse affecting enterprise AI assistants.
A June 2024 reference documented how prompt injection against GitHub Copilot Chat could be used to exfiltrate data, marking an earlier concrete example of prompt-injection abuse in AI coding assistants. This predates the ChatGPT Operator and BrowserOS prompt-injection developments already in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcedarkreading.com
Open sourcepivot-to-ai.com
Open sourcecysecurity.news
Open sourcesimonwillison.net
Open sourcesimonwillison.net
Open sourcesimonwillison.net
Open sourcesimonwillison.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.