Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securitydata-exfiltration-methodendpoint-software-vulnerability

Prompt Injection Risks in Agentic AI and AI-Powered Browsers

Updated 3mo agoFirst seen Feb 20, 20262 sources

Security researchers reported that prompt injection is enabling practical attacks against agentic AI systems that have access to tools and user data, and argued the industry is underestimating the threat. A proposed framing, “promptware,” describes malicious prompts as a malware-like execution mechanism that can drive an LLM to take actions via its connected tools—potentially leading to data exfiltration, cross-system propagation, IoT manipulation, or even arbitrary code execution, depending on the permissions and integrations available.

Trail of Bits disclosed results from an adversarial security assessment of Perplexity’s Comet browser, showing how prompt injection techniques could be used to extract private information from authenticated sessions (e.g., Gmail) by abusing the browser’s AI assistant and its tool access (such as reading page content, using browsing history, and interacting with the browser). Their threat-model-driven testing emphasized that agentic assistants can treat external web content as instructions unless it is explicitly handled as untrusted input, and they published recommendations intended to reduce prompt-injection-driven data paths between the user’s local trust zone (profiles/cookies/history) and vendor-hosted agent/chat services.

Share:
Prompt Injection Risks in Agentic AI and AI-Powered Browsers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 20, 20264mo ago

Trail of Bits publishes recommendations for securing AI agents

After the assessment, Trail of Bits published five recommendations for teams building AI agents, including ML-centered threat modeling, strict trust boundaries between system instructions and external content, systematic prompt-injection red-teaming, least-privilege tool access, and treating AI inputs as untrusted data. The write-up also noted that one exploit variant depended on misspellings in a fake warning to bypass fraud detection.

Trail of Bits demonstrates Gmail data exfiltration via Comet prompt injection

During the assessment, Trail of Bits built multiple proof-of-concept exploits showing that Comet could be induced to exfiltrate private Gmail content from an authenticated user session to attacker-controlled infrastructure when asked to summarize a page. The researchers identified four prompt injection techniques and showed multi-step attack flows using redirects, fragment collection, and social-engineering lures such as CAPTCHAs and fake system warnings.

Trail of Bits audits Perplexity's Comet browser before launch

Before Comet's launch, Trail of Bits performed an adversarial security assessment of Perplexity's LLM-powered browser assistant using its TRAIL threat-modeling approach. The review focused on how prompt injection delivered through attacker-controlled web pages could affect the agentic browsing assistant.

Feb 18, 20264mo ago

Researchers propose a seven-stage 'promptware' kill chain

The paper introduced a seven-stage kill chain for promptware, distinguishing prompt injection from jailbreaking and describing how attacks can progress to data exfiltration, lateral movement, IoT manipulation, or code execution depending on connected tools and permissions. It also highlighted persistence mechanisms through poisoned retrieved content and long-term memory features.

Researchers document three years of real-world prompt injection attacks

A research paper by authors from Tel Aviv University, Ben-Gurion University of the Negev, and Harvard University reviewed 36 real-world attacks over a three-year period and found that prompt injection incidents were becoming more sophisticated. The authors argued these attacks should be treated as a distinct malware class, which they call "promptware."

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Malware
2 linked
Affected products
4 linked
GmailGithub CopilotChatgptChatgpt
Organizations
6 linked
Trail of BitsPerplexityGoogleShutterstockInformation Security Media GroupGitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Prompt Injection Risks in Agentic AI and AI-Powered Browsers | Mallory