Following the emergence of AI chatbots like ChatGPT, Google Gemini, and Perplexity, the era of AI browsers has begun, with many companies launching internet browsers powered by artificial intelligence. Recently, Google added a Gemini to its search engine, and both Perplexity and OpenAI introduced their own AI web browsers named Perplexity and Atlas, respectively. These new tools provide exciting ways to browse the internet. However, it's important for users to be careful when using them, as not being cautious could put personal and financial information at risk.
AI browsers pose security dangers
Cybersecurity experts are cautioning that using a web browser powered by artificial intelligence (AI) might carry some risks. These advanced browsers come with special features such as indirect prompt injection that could potentially be misused by hackers. This could put your personal information at risk, including things like your files, passwords, and bank account details, which could result in serious cases of fraud.
Researchers from Brave have pointed out that certain AI browsers, like Perplexity, Comet, and Fellou, are especially prone to a specific type of problem called indirect prompt injection. This issue means that harmful commands hidden on websites could trick the AI into acting in ways that benefit criminals, putting users at risk. It's important to be cautious when using these new technologies.
The threat of prompt injection attacks
Technology giant IBM concurs, identifying prompt injection as a type of cyberattack where malicious inputs are disguised as legitimate prompts. This tactic can cause the leakage of sensitive information stored within AI systems. The danger is amplified if AI applications have access to confidential documents or APIs, which could result in substantial damage.
How to mitigate the risk
Experts currently believe that a complete, foolproof solution has not yet been found. Therefore, the most crucial step when using an AI browser is to ensure that user permission is required for any sensitive operation.
While OpenAI has integrated its AgentKit tools with the Guardrails security framework—an effort primarily aimed at securing AI agents—this measure appears insufficient for comprehensive security at this time. Ultimately, tech companies need to do more to ensure that their AI browsers are completely safe for everyday use.