Get the latest tech news
Anthropic’s auto-clicking AI Chrome extension raises browser-hijacking concerns
Malicious websites can embed invisible commands that AI agents will follow blindly.
Users can grant Claude permission to perform tasks like managing calendars, scheduling meetings, drafting email responses, handling expense reports, and testing website features. "I strongly expect that the entire concept of an agentic browser extension is fatally flawed and cannot be built safely," he wrote in an earlier post on similar prompt-injection security issues recently found in Perplexity Comet. Last week, Brave's security team discovered that Perplexity's Comet browser could be tricked into accessing users' Gmail accounts and triggering password recovery flows through malicious instructions hidden in Reddit posts.
Or read this on ArsTechnica