AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
August 5, 2026
Black Hat USA 2026 – Las Vegas – While AI-powered web browsers are getting more guardrails against prompt injections, it seems unlikely that the prevalent threat is going anywhere anytime soon.
At Black Hat USA 2026, Brave Software security engineer Artem Chaikin hosted a session titled "Attacking and Defending AI Browsers." The session aimed to illuminate the security reality behind modern web browsers, which increasingly integrate AI assistants that can navigate and interact with web applications on users' behalf.
As is so often the case with agentic or agentic-like functionality, these browser functions are vulnerable to indirect prompt injections through the right web page, leading to data exfiltration and account takeover. Chaikin said every browser he analyzed proved vulnerable to prompt injections.









