LayerX BioShocking prompt injection against agentic browsers
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers demonstrated BioShocking, a prompt-injection technique that pushed six agentic browsers and plugins past guardrails and made them copy login credentials for exfiltration. The proof-of-concept raised immediate risk for logged-in accounts, open tabs, and private repositories across AI browser products. The test covered OpenAI's ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension.
Related Happenings
OpenAI ChatGPT Atlas BioShocking fix
Advisory/Mitigation
H score34
First: 01.07.2026 00:50
Last: 01.07.2026 00:50
Sources 1
How related:
The researchers say that OpenAI was the only vendor that has implemented a working fix for BioShocking in its ChatGPT Atlas browser.
About this happening:
OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
OpenAI ChatGPT Atlas BioShocking fix
Advisory/MitigationHow related: The researchers say that OpenAI was the only vendor that has implemented a working fix for BioShocking in its ChatGPT Atlas browser.
About this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...
AI browser guidance to prompt before reading logged-in accounts and limit agent access
Defensive Guidance
H score28
First: 30.06.2026 11:37
Last: 30.06.2026 11:37
Sources 1
How related:
To shut the attack down, LayerX wants AI browsers to ask before reading from logged-in accounts.
About this happening:
LayerX recommends tightening AI browser agent mode so the browser must ask before reading from logged-in accounts, reducing the risk of credential theft through ...
AI browser guidance to prompt before reading logged-in accounts and limit agent access
Defensive GuidanceHow related: To shut the attack down, LayerX wants AI browsers to ask before reading from logged-in accounts.
About this happening: LayerX recommends tightening AI browser agent mode so the browser must ask before reading from logged-in accounts, reducing the risk of credential theft through ...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
BrowserOS WebPromptTrap patch release (0.32.0)
Security Patch Release
H score11
First: 29.05.2026 21:07
Last: 29.05.2026 21:07
Sources 1
About this happening:
BrowserOS patched WebPromptTrap in version 0.32.0, closing an indirect prompt-injection flaw that could trick users into approving an authorization step inside the...
BrowserOS WebPromptTrap patch release (0.32.0)
Security Patch ReleaseAbout this happening: BrowserOS patched WebPromptTrap in version 0.32.0, closing an indirect prompt-injection flaw that could trick users into approving an authorization step inside the...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
Trend
H score76
First: 05.05.2026 13:30
Last: 05.05.2026 13:30
Sources 1
About this happening:
A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
TrendAbout this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Timeline
-
24.06.2026 19:05 4 articles · 21d ago
BioShocking tricks AI browsers into copying login credentials
Technical Analysis UpdateLayerX researchers demonstrated BioShocking against six agentic browsers and plugins, including OpenAI's ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, by using a malicious web page with a puzzle that rewarded deliberately wrong answers until the agent treated its context as fiction. After the rigged puzzle, the agent was told to open a page called /code and copy the contents of a text box that redirected to the victim's work GitHub repository, allowing the agent to pull out SSH credentials. LayerX said OpenAI fixed the issue in ChatGPT Atlas, Perplexity closed its report without acting, and Anthropic attempted a fix that failed, then urged browser makers to require user confirmation before reading from logged-in accounts, flag when an agent is told the usual rules no longer apply, and let users limit what an agent can touch.
Show sources
- Researchers Trick AI Browsers Into Leaking Credentials — www.infosecurity-magazine.com — 24.06.2026 19:05
- Researchers Trick AI Browsers Into Leaking Credentials — www.infosecurity-magazine.com — 24.06.2026 19:05
- New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials — thehackernews.com — 30.06.2026 11:37
- New BioShocking attack manipulates AI browser into data theft — www.bleepingcomputer.com — 01.07.2026 00:50