AI browsers can be hijacked with just a hashtag in a URL, leaving users exposed without noticing anything at all




  • Hidden URL fragments allow attackers to manipulate AI assistants without user knowledge
  • Some AI assistants transmit sensitive data to external endpoints automatically
  • Misleading guidance and fake links can appear on otherwise normal websites

Many AI browsers are facing scrutiny after researchers detailed how a simple fragment in a URL can be used to influence browser assistants.

New research from Cato Networks found the “HashJack” technique allows malicious instructions to sit quietly after a hashtag in an otherwise legitimate link, creating a path for covert commands that remain invisible to traditional monitoring tools.


https://cdn.mos.cms.futurecdn.net/tDa3WLvG3EBawodkpXTvqP-1920-80.png



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img