This is in related to another post on this forum.
NBC is running a story where some AI browsers (browsers which have AI agents embedded in them from get go) may have vulnerabilities related to prompt injection and other privacy concerns associated with them. It mentions 3 AI browsers,
- Open AI’s Atlas,
- Perplexity’s Comet
- Opera’s Neon
These vulnerabilities allow for attacks on email accounts, Google Drive, Microsoft Word and possibly their bank accounts too. According to the article
The “site” in question needs to have certain text that is coded to be invisible to the user but works as an instruction for the AI agent to execute. Other vectors could include items like hide malicious code in Reddit posts with a “spoiler” tag, designed to hid the text. Or hiding malicious code for AI agents on a website which a human can miss, by playing with text and background color or other means.
This is not what is the most disturbing aspect of this article. Some of these Generative AI companies, who are making these browsers are putting the onus on to the user. Their approach has been
Also they have been disparaging these findings by casting doubts on the intents of those reporting the issues
This is not going to end well. These new generative AI companies are focusing on anything but privacy and security. If users saying “Thank You” at the end of the generative AI prompts is causing heart burn for some of these companies, this is going to burn a bigger hole for them.
Hope this is not a hatchet job by NBC.
Other References:
“Do Anything Now”: Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models