With 1 Extension: $20K in Bounties from Anthropic, Perplexity, Google, Microsoft (forever.security)

🤖 AI Summary
A new security research effort named "BragJack" has revealed significant vulnerabilities in five major web browsers—Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome—exploiting their built-in AI assistants. The researchers discovered that these vulnerabilities, allowing unauthorized control over critical browser functions like accessing user files, taking screenshots, and even controlling the microphone and camera, stem from a fundamental design flaw that impacts how the browsers handle requests between their AI components and the extension ecosystem. This work has led to $20,000 in bounties from tech giants including Google and Microsoft, highlighting the high stakes of AI integration into everyday technologies. The implications for the AI and machine learning community are profound. The researchers introduced a novel attack technique called "Prompt-Forcing," which allows attackers to fully control the prompts sent to the AI, enabling sophisticated and flexible exploitation without the need for traditional coding methods. This new approach bypasses existing security measures, raising concerns about endpoint security as it allows malicious actors to execute commands undetected. As AI continues to be integrated into web browsers, this research underscores the necessity for a reevaluation of security protocols surrounding these AI agents, urging developers to bolster safeguards against such vulnerabilities.
Loading comments...
loading comments...