Saturday, 29 November 2025
33.2 C
Singapore
29.5 C
Thailand
23.9 C
Indonesia
28.5 C
Philippines

AI browsers vulnerable to covert hacks using simple URL fragments, experts warn

Experts warn AI browsers can be hacked with hidden URL fragments, posing risks invisible to traditional security measures.

Recent research has revealed that many AI browsers may be at risk from a novel hacking method that exploits hidden text in URLs. Experts say the technique, called “HashJack,” allows attackers to insert commands after a hashtag in an otherwise legitimate link, which the browser assistant processes without alerting users or servers.

How the HashJack technique works

Cato Networks’ study demonstrated that HashJack lets malicious instructions remain hidden in the browser. The assistant interprets the text locally, meaning it does not transmit the instructions to the server. Users continue to see a normal web page while the browser quietly executes the commands.

Tests revealed that certain AI assistants could autonomously take action after encountering these fragments, including sending data to external locations controlled by attackers. Others generated misleading guidance or promoted links that appeared to be from trusted sources, creating the impression of a normal session while altering the information presented to the user. The page displayed in the browser remained unchanged, making the intrusion difficult to detect without close monitoring of the assistant’s behaviour.

Industry response and challenges

Major technology firms have been notified of the vulnerability, but responses have varied. Some companies issued updates to their AI browser features, while others considered the behaviour to be expected under existing design logic.

Defending against this type of indirect prompt manipulation depends on how each AI assistant interprets hidden instructions on a page. Traditional traffic inspection tools only monitor URL fragments that leave the device. Because HashJack fragments are processed locally, conventional security measures offer limited protection. Experts say defenders must look beyond network-level monitoring and examine how AI assistants integrate with browsers, with particular attention to local behaviour invisible to users.

Stronger protection requires stricter endpoint security and tighter firewall rules, though these measures do not fully address the visibility gap. HashJack highlights a vulnerability unique to AI-assisted browsing, where even legitimate websites can be weaponised without leaving conventional traces. Awareness of these limitations is essential for organisations deploying AI tools, as traditional monitoring methods cannot fully capture such threats.

Tips for staying safe online

Experts recommend limiting the personal information shared online and monitoring financial accounts for unusual activity. Using unique, complex passwords and verifying URLs before logging in can reduce the risk of attacks. Users should also exercise caution with unsolicited messages or calls claiming to be from financial institutions and ensure antivirus software and firewalls are enabled. Identity theft protection services can help monitor sensitive information, though experts stress that even sophisticated measures cannot eliminate the risk from AI-driven attacks and phishing campaigns. Consistent implementation across all devices and networks remains key to maintaining security.

HashJack serves as a reminder that, while convenient, AI browsers introduce new cybersecurity risks that require careful oversight.

Hot this week

Epic CEO questions the relevance of AI labels in game stores

Epic CEO Tim Sweeney questions the need for AI labels in game stores amid industry debates over transparency and the future role of AI.

Battlefield 6 launches week-long free-to-play trial for new players

Battlefield 6 launches a week-long free trial with multiple playlists, map access, and progress carryover ahead of its Winter Offensive update.

Kaspersky reports surge in shopping phishing and gaming-related attacks in 2025

Kaspersky reports 6.4 million shopping phishing attempts and more than 20 million gaming-related attacks detected in 2025.

ShadowV2 botnet spotted during AWS outage, researchers warn of possible return

ShadowV2 botnet briefly emerged during the AWS outage, targeting IoT devices, raising concerns about future cyberattacks.

Google limits free Nano Banana Pro image generation due to high demand

Google is reducing free Nano Banana Pro and Gemini 3 Pro usage due to high demand, limiting daily access while paid plans remain unchanged.

Slop Evader filters out AI content to restore pre-ChatGPT internet

Slop Evader filters AI-generated content online, restoring pre-ChatGPT search results for a more human web.

Lara Croft becomes gaming’s best-selling heroine amid new Tomb Raider rumours

Lara Croft becomes gaming’s best-selling heroine as new Tomb Raider rumours fuel excitement.

Cronos: The New Dawn drives major profit surge for Bloober Team

Bloober Team reports record Q3 2025 results as Cronos: The New Dawn drives a major surge in global sales and profit.

China warns of growing risk of bubble in humanoid robot industry

China warns of a potential bubble in the humanoid robot industry, raising concerns about market saturation, investment risks, and global impact.

Related Articles

Popular Categories