Two Chrome extensions looking exactly like ChatGPT and Claude picked up more than 900,000 installs in January 2026. All before researchers caught them scraping full conversation histories and shipping the data out every 30 minutes. That’s just the tip of the iceberg of what has actually gone wrong with tools people call AI browsers.
An AI browser agent runs with your logins, reads your tabs, and acts on them. Every risk covered in this piece has already happened some way or the other with real users.
An AI browser’s only safe to use when you tighten its permissions, don’t involve accounts that would hurt to lose, and keep it confirming actions at every step. So, I’ll talk about what an AI browser is, its risks, how to use one safely, and definitely how to choose one.
Key Takeaways
- Prompt injection hijacks the agent through text hidden on a page.
- Stolen session cookies let an attacker skip your password entirely.
- Broad permissions turn one compromised extension into access across your camera, files, and inbox.
- None of this gets fixed by picking a well-reviewed browser off a list. It gets fixed by tightening settings, separating sensitive logins, and keeping the agent on a confirm-before-acting setting.
What Is an AI Browser, and How Is It Different?
An AI browser is a regular browser with an agent built in that can read a page, click buttons, fill in forms, and carry out multi-step tasks, not just answer questions about what’s on screen.
Google’s Gemini in Chrome, Perplexity Comet, and OpenAI’s ChatGPT Atlas are the three most discussed examples right now, and each one currently lives at the crossroads of assistive (summarize, answer, suggest) and agentic (log in, buy, submit) depending on the permissions it’s given.

But here’s a simple difference. A normal browser is a window. An AI browser is a window with a pair of hands attached. So, if you’re logged into your bank, your email, and your work tools across different tabs, the agent inherits access to all of it, and it decides what to click based on text it reads on a page, the exact channel an attacker can write to.
A University of Washington study tested 7 agentic browsers and demonstrated a working cross-origin data-theft attack against ChatGPT Atlas under controlled conditions. Remember, that’s one of the best-funded products in the category, tested and broken within months of its public launch.
Are AI Browsers Safe to Use?
Yes, but with real precautions. Every major AI browser released so far has shipped with at least one documented prompt injection or data-exposure issue in its first year on the market. Like Perplexity Comet, which its maker attempted to patch twice without fully closing the gap. Prompt injection currently ranks as the top security issue in the OWASP list for LLM applications, ahead of every other category.
The risk is structural, not a bug that gets patched once and disappears.
The agent’s entire job is to read untrusted content and turn it into actions inside a trusted context. Every fix narrows that gap. But none of the current designs close it. And that’s why researchers keep finding new variants of the same underlying flaw under new names.
The Main AI Browser Security Risks
These 4 risks map to how the agent sees a page, stores what it learns, and acts on your behalf. This section covers how each attack actually works.
| Risk | How the attack works | What an attacker gains |
| Prompt injection | Hidden text on a page overrides the agent’s instructions | Control over the agent’s next actions |
| Cookie theft and session hijacking | Session tokens are extracted or reused without a password | Full account access with no login alert triggered |
| Over-permissioned agents | Broad extension permissions reach far past the task at hand | Access to cookies, passwords, and full page contents |
| Data privacy and oversharing | Page content or keystrokes are sent to a model provider for processing | A copy of data the user never intended to share |
Prompt injection attacks
Prompt injection is a hidden instruction planted somewhere that the agent can read, such as a webpage, a PDF, an image, even a file’s metadata. The agent can’t reliably tell the difference between an instruction from you and one hidden in the page it’s summarizing, so it follows both.
The mechanism has been demonstrated for years.
A Stanford student got Microsoft’s Bing Chat to reveal its own hidden instructions just by typing ignore previous instructions into the chat window. That’s the direct version. The indirect version is far worse for an AI browser specifically, because the malicious text doesn’t need to come from you at all. Brave’s security team hid instructions in an image using faint light-blue text on a yellow background, invisible to a human glancing at the screen but perfectly legible to the AI reading it.
But defenses do exist.
Microsoft Research has a technique called spotlighting that marks the difference between your prompt and retrieved web content. And some agents now separate the planning model from the reading model so a compromised page can’t directly trigger an action.

Cookie theft and session hijacking
Cookie theft is the extraction of a session token. It’s the small file that keeps you logged in without re-entering your password every time. Session hijacking is the next step. Here, an attacker reuses that token to act as you.
An AI browser makes this far worse for one specific reason.
The agent operates across every authenticated session in your browser at once, treating your bank tab and a random news article the same way once it decides both are relevant to a task. Security researchers call this excessive agency, the agent breaking application boundaries a human would never cross without thinking twice.
One documented case had a very visible pattern. A Comet user’s email address was pulled from their Perplexity account page while the agent was simply asked to summarize an unrelated Reddit thread. Nobody clicked a phishing link. The agent pulled account data as a side effect of doing something else.
Over-permissioned agents and account access
Browser permissions like tabs, activeTab, scripting, and cookies sound technical, but each one hands an extension specific reach, like reading every open tab, touching page content, or grabbing session tokens. And across enterprise environments, 53% of AI-related browser extensions carry high or critical permission scopes capable of reaching cookies, passwords, and full page contents.
The account-access risk just starts compounding from here. One over-scoped agent doesn’t just expose the site you’re on; it can chain into whatever else is logged in nearby; it could be emails, cloud storage, or even work tools.
The same report documented a VPN extension with more than 8 million users across Chrome and Edge that quietly pushed an update intercepting AI conversations with ChatGPT, Claude, Gemini, and 5 other platforms, then sold the harvested conversations to advertisers, without asking existing users to re-consent.
The issue is that most people never check what permissions an extension already has. And the risk thrives inside that gap.
Data privacy and oversharing.
AI browsers often send page content, keystrokes, or browsing history to a model provider so the agent has enough context to help. Chrome’s “Help me write” feature sends text, page content, and URLs to Google. Microsoft Edge accesses browsing context and history once Copilot permission is granted. Neither’s a secret, but both mean a page you assumed was private, an internal dashboard, a draft email, a medical portal, may have already left your device before you thought to check.
The difference is local vs. cloud processing.
A feature that runs entirely on your device doesn’t have this problem, because there’s nothing to intercept in transit. A feature that sends context to a server does, and most AI browser settings don’t make that distinction obvious at a glance.
How to Use an AI Browser Safely: A Practical Checklist
Everything above explains the threat. This section covers the settings and habits that will actually help you reduce it.
Review and restrict browser permissions.
Open your browser’s extension settings and check what permissions each AI tool has. And then revoke any access it doesn’t need for the tasks you actually use it for. And set the browser to ask before granting anything new. Always audit the extension version histories, since permissions have quietly expanded through auto-updates in more than one documented case.
Also check connected apps under your Google or Microsoft account settings, separate from the browser itself. An agent with your OAuth access to your Drive months ago keeps that access until you manually pull it.

Isolate sensitive accounts and logins.
Keep banking, work admin, and anything you’d hate to lose out separate from your AI browser.
- Log out of sensitive accounts after you’re done, rather than leaving the tab open indefinitely.
- Never let the agent act on a banking or admin page, even for something as small as checking a balance.
- If your browser supports multiple profiles, put the AI agent in one and your financial logins in another.
Watch for prompt injection red flags.
The clearest signal that something’s wrong is an agent proposing an action you didn’t ask for; like an unexpected purchase, a draft addressed to someone you don’t recognize, a request to enter payment details mid-task. Malwarebytes documented exactly this scenario with a booking request as simple as find the cheapest flight to Paris and book it, where a hidden instruction on a travel site could redirect payment details to an attacker instead of the airline.
Keep the agent in review-and-confirm mode rather than fully autonomous mode, especially for anything involving money or account settings.
Keep session data and cookies protected
Clear cookies on a regular schedule, particularly after using the agent on an unfamiliar site. Set shorter session timeouts where your accounts allow it, so a stolen token has a smaller window to be useful. Turn on two-factor authentication everywhere it’s offered.
How to Choose a Secure AI Browser
Check these five things:
- Whether sensitive tasks are processed locally or sent to the cloud.
- How clearly the vendor documents what data it collects.
- How granular the permission controls actually are.
- Whether the default behavior is confirm-before-acting or fully autonomous.
- Whether the vendor publishes its own security disclosures instead of waiting for a researcher to find them first.
Final Thoughts
AI browsers are early technology, and right now the burden of using them safely is with the person clicking, not the company that built the agent. That will shift over time as defaults get tighter and vendors face more pressure after incidents like the ones in this piece, but it’s our duty to maintain safe distance.
Treat the agent the way you’d treat a new employee with your passwords; useful, but don’t trust everything on day one. Give it access as it earns it, not the other way around.
For more info on tech and AI, visit Yaabot.
FAQs
Not directly, but a stolen session cookie can bypass your password entirely. Keep two-factor authentication on and clear cookies regularly so a stolen token doesn’t stay useful for long.
It’s real and documented, ranking as the top security issue in the OWASP list for LLM applications. It’s uncommon for casual users so far, but proven repeatedly against major products.
Often, yes. Features like Chrome’s “Help me write” send page text and URLs to the provider for processing. Check whether a feature runs locally before using it on sensitive pages.
Not by default. Never allow the agent to log in directly to a financial site, and always use a different browser or profile to log in to your bank account.
Most browsers let you disable the agent feature entirely in settings, separate from turning off individual permissions. That’s the safest default for sessions involving sensitive accounts.

