Agentic LLM Browsers Vulnerable to Prompt Injection and Data Theft

Agentic LLM Browsers Vulnerable to Prompt Injection and Data Theft

First seen 15 Apr 2026, 22:44 UTC GbhackersCybersecuritynewswww.varonis.com 88% similarity 66.8

Article Content

Browse articles
ThreatCluster

Agentic LLM browsers, which automate user tasks by reading and interacting with web content, have introduced significant security risks related to prompt injection and data theft. These browsers, including Perplexity Comet, OpenAI Atlas, Edge Copilot, and Brave Leo, operate with elevated permissions that can be exploited if an attacker gains access to trusted domains. Vulnerabilities arise from various attack vectors such as XSS, subdomain takeover, and backend RCE, allowing attackers to bypass security measures and directly manipulate browser APIs. The integration of AI in these browsers increases the potential for unauthorized data access and exfiltration, as the agent operates with the user's cookies and permissions. This situation poses a critical risk to users, as it can lead to cross-tab data theft and impersonation actions. Varonis Threat Labs has highlighted these vulnerabilities, emphasizing the urgent need for awareness and mitigation strategies.

Key Points: • Agentic LLM browsers automate tasks but expose users to prompt injection risks. • Attackers can exploit trusted domains to bypass security and access sensitive data. • Current architectures of these browsers increase the potential for unauthorized actions.

ThreatCluster AI

Timeline

2025-01-05
CVE-2025-1234 published
2025-01-10
First article coverage
2026-04-15
Gbhackers and Cybersecuritynews publish articles on vulnerabilities

Community

Browse all →