- The short answer
- The core risk is indirect prompt injection. An AI browser agent cannot reliably tell the
- difference between your instructions and text it finds on a page, so a web page can
- issue it commands.
- This matters more than ordinary web vulnerabilities because the agent runs inside
- your browser, holding your logged-in sessions. Brave's conclusion after testing was
- that the same-origin policy and CORS are effectively useless against it.
- It is not one vendor's bug. Comet, Fellou and Opera Neon have all been found
- vulnerable to the same class of attack, and Unit 42 reports finding payloads in live web
- telemetry rather than only in laboratories.
- Nobody has solved it. The single most effective thing you can do today is not run an
- agent in a browser that is signed in to anything you care about.
Built from published vulnerability research by Brave and Palo Alto Networks Unit 42, read 17 September 2026. No speculative threats.
What a browser agent security risk actually is
A browser agent is an AI that drives a real browser with your permissions — clicking, typing, navigating, reading pages. Perplexity Comet, Opera Neon, Fellou and the agent modes now appearing in mainstream browsers all fit the description.
The risk that dominates every published disclosure is indirect prompt injection. Direct injection is when you type something adversarial yourself. Indirect injection is when the agent reads something adversarial while doing what you asked, and cannot tell that it came from a stranger rather than from you.
That distinction sounds academic until you see the chain it enables.
One documented attack, start to finish
Brave’s security team published this against Perplexity Comet in August 2025. It remains the clearest illustration of the class.

Brave’s published proof of concept. The victim clicks one button.
Two details deserve attention. The first is step 5: the instructions directed the agent to a domain with a trailing dot appended, which is technically a different host from the real one and therefore sits outside the existing authenticated session. That is a piece of DNS trivia being used as an attack primitive, and it is the kind of thing a human would notice in a URL bar and an agent did not.
The second is that the malicious content was a Reddit comment. The attacker did not need to control a website. They needed to be able to post on one.
The disclosure did not go smoothly
Brave reported the flaw on 25 July 2025. Perplexity acknowledged it and shipped a fix on 27 July. Retesting on 28 July showed the fix was incomplete. By 13 August a further round of testing suggested it was patched, and Brave published on 20 August.
Then they appended an update to their own post: on further testing after publication, they found Perplexity still had not fully mitigated the attack, and re-reported it. That is worth holding on to when a vendor tells you a prompt-injection issue is fixed.
Why existing browser security does not help

The protections that stop a malicious site reading your bank tab do not apply to an agent.
Everything the browser does to keep sites apart assumes the attacker is a site. The same-origin policy, CORS, SameSite cookies — all of it exists to stop origin A reading origin B.
An agent is not origin A. It is a privileged process inside your browser that is allowed to visit both. When a page persuades it to go and read your email, no cross-origin request is made, no policy is violated, and nothing in the security model has been broken. The agent simply did what it was told, by the wrong person.
Brave put it plainly: when an AI assistant follows malicious instructions from untrusted webpage content, traditional protections such as same-origin policy or CORS are all effectively useless. The attack is, in their phrasing, indirect in interaction and browser-wide in scope.
It is not one product’s problem

Published disclosures against agentic browsers. Same class of flaw, different vendors.
The Fellou finding is the most instructive of the set, because it lowers the bar further. In Comet the victim had to click summarize. In Fellou, Brave found that simply asking the browser to navigate to a page caused the page’s content to be sent to the model, where visible instructions could override the user’s intent. No summarize step, no hidden text required.
Brave’s June 2026 follow-up closes off the workaround that this site’s readers tend to reach for first. Indirect prompt injection affects cloud and on-device models alike — running the model locally does not eliminate the risk. The vulnerability is in how the context is assembled, not in where inference happens. If you are set up for running LLMs locally, you have solved a privacy problem, not this one.
Where the instructions hide
Both research groups publish the categories, so there is no value in coyness about them. Knowing what to look for is the point, and none of this is operational detail an attacker lacks.

Documented hiding places. All of them are invisible or near-invisible to a human reader.
The screenshot vector is the one most people do not anticipate. Comet lets users capture a screenshot and ask questions about it. Brave hid instructions as faint light-blue text on a yellow background — unreadable to a person, recovered cleanly by text recognition, and passed to the model with no marking to say it came from an image rather than from the user.
Unit 42 documented 22 distinct techniques in real detections, frequently stacked on a single page so that if one layer is filtered another survives. Their catalogue includes multilingual repetition, so a filter tuned to English misses the Russian copy, and syntax breakout characters intended to close the surrounding data structure and inject new fields.
Is this actually happening, or is it a lab result?
A fair question, and the honest answer has two halves.

Unit 42’s telemetry findings, including the caveat they print themselves.
Unit 42’s position is that prior research concentrated on proof-of-concept attacks, while their own large-scale telemetry shows indirect prompt injection is no longer merely theoretical but is being actively weaponized. The intents they catalogue are commercial rather than exotic: getting scam adverts past AI moderation, pushing a phishing site impersonating a betting platform, destroying data, and extracting an agent’s own system prompt.
The other half is the caveat they publish themselves. On the ad-review case they note they are not aware of any confirmed real-world instance where such an attack succeeded against a deployed ad-checking agent. Payloads existing in the wild is not the same as attacks landing. Both things are true, and an article that reports only the scarier half is not being straight with you.
The defensible summary: the attack is proven in controlled conditions against multiple shipping products, and attackers are demonstrably seeding the web with payloads in anticipation. Whether your particular agent has been hit is unknowable from published data.
What to do about it

Only the left column is available to you today.
The one that matters most
Use a separate browser profile for agent work, signed in to nothing. Every published attack in this article derives its severity from the agent inheriting an authenticated session. Remove the sessions and the same injection produces an agent that reads a page and achieves nothing.
This is unglamorous and it is the entire ballgame. An injection that hijacks an empty profile is a curiosity. The same injection in the window where your bank, your email and your cloud console are logged in is the Brave demonstration.
Treat summarize as a privileged action
The mental model most people carry is that reading is safe and acting is risky. These disclosures invert that. Asking an agent to summarize an untrusted page is the trigger in two of the four cases above, and in Fellou merely navigating was enough. If the page is one you would not run a script from, do not point an agent at it either.
Keep confirmation prompts on
Brave’s proposed mitigation list includes requiring explicit user interaction for security and privacy sensitive actions, every time, regardless of the agent’s plan. Where your tools offer that, leave it on. We wrote about the equivalent trade-off in coding agents in what –dangerously-skip-permissions actually does — the reasoning transfers directly, because the threat is the same one.
Verify by result, not by report
A compromised agent will describe a successful, innocent task. Check the actual state afterwards: sent mail, account activity, files changed, anything with a transaction log. The agent’s own account of what it did is generated by the model an attacker may be steering.
What vendors have not fixed
Brave’s four proposed mitigations are worth stating as a scorecard, because they describe the shape of a solution nobody has fully shipped.
- Separate user instructions from page content before either reaches the model, and treat page content as permanently untrusted.
- Treat the model’s proposed actions as potentially unsafe and check them independently against what the user actually asked for.
- Require genuine user interaction for sensitive actions, no matter what the agent’s plan says.
- Isolate agentic browsing from normal browsing, with minimal permissions, so you cannot wander into agent mode by accident.
Their own assessment, after four rounds of research across the category: until there are categorical safety improvements across the whole browser landscape, agentic browsing is inherently dangerous and should be treated as such.
Frequently asked questions
What is the main security risk with browser agents?
Indirect prompt injection. The agent cannot reliably distinguish your instructions from text it reads on a web page, so a page can issue it commands that run with your logged-in privileges.
Are AI browsers safe to use?
Not for sensitive sessions. Brave’s assessment is that agentic browsing is inherently dangerous until the category ships categorical safety improvements. Using a separate profile signed in to nothing removes most of the severity.
Which AI browsers have documented vulnerabilities?
Perplexity Comet (twice), Fellou and Opera Neon all had prompt injection flaws disclosed by Brave between August and October 2025.
Does the same-origin policy protect me?
No. Brave found it effectively useless here, because the agent already operates inside your browser with your privileges rather than making a cross-origin request.
Does running a local model fix this?
No. Brave’s June 2026 research found indirect prompt injection affects cloud and on-device models alike. The flaw is in how context is assembled, not where inference runs.
Is prompt injection happening in the real world?
Unit 42 reports finding payloads in large-scale web telemetry and describes the technique as actively weaponized. They also note they cannot confirm real-world success against every target type they observed being aimed at.
How do attackers hide the instructions?
Invisible text, HTML comments and non-rendered markup, text camouflaged inside images and recovered by OCR, several layers of encoding, and repetition across languages. Unit 42 catalogued 22 techniques.
What is the single best precaution?
Run agents in a browser profile that is not signed in to your email, bank, or work accounts. Every published attack draws its severity from the sessions the agent inherits.
Related reading
For the equivalent problem in coding agents, see –dangerously-skip-permissions: what it actually does. For keeping inference off third-party servers entirely, running LLMs locally and the Open WebUI guide cover the setup — with the caveat above that local inference does not solve injection. If you are deploying automated workflows outside the browser to isolate execution permissions, review our breakdown of n8n pricing and self-hosted runner costs.
Primary sources, read 17 September 2026: brave.com/blog/comet-prompt-injection (20 Aug 2025) · brave.com/blog/unseeable-prompt-injections (21 Oct 2025) · brave.com/blog/prompt-injection-flaw-opera-neon (31 Oct 2025) · brave.com/blog/indirect-prompt-injection (8 Jun 2026) · unit42.paloaltonetworks.com/ai-agent-prompt-injection.
Leave a Reply