the-browser-assistant

The browser gets an AI assistant that browses for you—and runs with all your accounts open. A command hidden on a page can instruct it.

Browser developers are adding an AI assistant that can act independently on the page: Copilot in Microsoft Edge, Gemini in Google Chrome, and Comet from Perplexity. You ask it to summarize an article, compare products, or fill out a form, and it navigates and performs the task—using the sessions you already have open in that browser: email, online banking, admin dashboards, and work files.

This is where the risk lies. The assistant cannot distinguish between the content of a web page and a command issued by you. Researchers at Cato Networks have demonstrated a technique called “HashJack,” which hides an instruction within a regular web address and uses it to manipulate AI assistants in Edge, Chrome, and Comet. Previously, the security team at Brave had highlighted the same type of issue: instructions hidden within a page—white text on a white background, comments in the code, and even text invisible to the naked eye but readable from a screenshot.

The practical implications are serious. In the demonstrations, the assistant was instructed to retrieve a one-time code from an email and log into the user’s online banking portal—because it was running with the user’s credentials. No need to click on a file or steal a password: all the assistant had to do was “read” the page prepared by the attacker.

The troubling part is that manufacturers openly admit that there is still no reliable fix for command injection. Every browser-based AI assistant demonstrated so far has been susceptible to being tricked in this way. So protection doesn’t come from a patch you’re waiting for, but from how you choose to use the tool.

For a small business, the concept is simple: anyone on the team can launch such an assistant with a single click, in the browser they use anyway. And from that moment on, a malicious page acts as if it had the user’s permissions.

Here's what you need to do, specifically:

  • Keep sensitive accounts—banking, work email, admin dashboards—in a regular browser, without an AI agent layer.
  • Decide within your company which browser-based AI assistant is approved and who is authorized to enable it. Write down the rule, even if it’s just one paragraph.
  • Don’t let the assistant act automatically on pages accessed via email links or from unknown search results.

This article was generated with AI assistance.

Request a quote

← All news