Convince a chatbot it’s playing a game, and it’ll hand a stranger your login. That’s not a hypothetical. Security firm LayerX did exactly that to six different AI browsers and assistants, including OpenAI’s ChatGPT Atlas, Perplexity’s Comet, and Anthropic’s Claude browser extension. The attack, dubbed BioShocking, tricked the agent into copying a user’s credentials and shipping them off to an attacker-controlled endpoint. No exploit, no memory corruption, no zero-day. Just a persuasive prompt.
If your cybersecurity model assumes the browser is a dumb pipe that renders pages and obeys the user, the last year of AI-in-the-browser features just rewrote that assumption out from under you. The browser now reasons, acts, and gets talked into things. And attackers have noticed.

Install An Assistant, Inherit Its Gullibility
Here’s the mechanism, stripped of the marketing gloss. An agentic browser doesn’t just display a web page. It reads the page, treats the content as context, and acts on your behalf. BioShocking exploits the seam between “content the agent should summarize” and “instructions the agent should follow.” Hide the right words on a page, frame the request as a harmless puzzle, and the agent helpfully autofills a credential field and posts it somewhere it shouldn’t.
This is prompt injection wearing a credential-theft costume. The agent has access to your session, your autofill, your logged-in state. When it gets socially engineered, it’s not a person clicking a bad link. It’s software with your permissions doing the clicking, and it doesn’t pause to wonder why a trivia game needs your bank password.
Now pair that with the other half of the week’s news. Microsoft’s threat researchers flagged a malicious Chromium extension that spoofs Perplexity AI, the real answer engine, and uses Manifest V3 APIs to quietly redirect your search traffic through intermediary infrastructure. Same playbook, different layer: ride the credibility of a trusted AI brand, then abuse legitimate browser APIs to do something the user never agreed to.
Only a handful of the AI tools tested resisted. Six were talked into leaking. The brand on the box told you nothing about whether the thing inside could be conned.
The connective thread is ugly and simple. Attackers are weaponizing the word “AI” in two directions at once. They impersonate trusted AI products to get installed, and they manipulate genuine AI features to act against the user once they’re running. Either way, the browser becomes the insider.
The Browser Is Now Inside Your Trust Boundary
For years your firewall, your threat detection stack, and your endpoint controls all rested on a quiet assumption: the user is the decision-maker, and the browser executes their intent. Brute-force defenses watch login attempts. Threat-protection tooling grades downloads by reputation. Everything keys off the idea that there’s a human in the loop making choices.
An agentic browser breaks that. The agent makes choices. It can be instructed by any web page it visits, and it carries the user’s full authenticated context while doing it. From the network’s point of view, the credential exfiltration in BioShocking looks like a normal HTTPS POST from a normal browser session. No malware signature fires. No brute-force counter ticks up. The traffic is trusted because the process is trusted.
That’s why this matters more than another extension-of-the-week story. You can’t perimeter your way out of an attack that originates from inside an approved, signed, legitimately-installed tool acting on legitimate user permissions. Defense in depth has to extend into the browser itself, because the browser stopped being a passive client and became an autonomous agent with your keys.

What To Do Before Your Help Desk Gets The Call
You don’t need to ban AI browsers to survive this. You need to treat them as privileged, untrusted-by-default software and govern them accordingly. Start now, then build the ongoing discipline.
Immediate moves, this week:
- Inventory what’s actually installed. Find every AI browser, browser assistant, and agentic extension across your fleet. You can’t govern what you can’t see, and shadow installs are the norm here.
- Enforce an extension allowlist through enterprise browser policy. Block sideloading and unknown-publisher extensions outright. The fake-Perplexity extension only works if a user can install it.
- Strip credential access from agents. Disable browser-managed password autofill on machines running agentic features, and move secrets into a vault that requires explicit, per-use human approval.
- Watch for the exfil pattern. Tune threat detection to flag outbound POSTs to newly-seen domains immediately after a browser-agent session, and alert on search traffic being redirected through unfamiliar intermediaries.
Ongoing security hardening that pays off past this news cycle:
- Make MFA phishing-resistant. Passkeys and hardware tokens don’t autofill into a chatbot’s text box the way a stored password does, which blunts the whole BioShocking class of trick.
- Pin and review extension versions. A clean extension today can ship a malicious update tomorrow; treat the supply chain into your browser like any other dependency.
- Write the agent into your incident response runbook. Decide in advance how you revoke sessions, rotate credentials, and isolate an endpoint when an AI agent, not a human, is the one that leaked.
- Train people on the new social-engineering surface. The lure isn’t always aimed at the user anymore. Sometimes it’s aimed at the assistant sitting in their browser, and the user never sees it happen.
The uncomfortable takeaway for anyone running cyber security operations: the most dangerous account on your network might be the one that belongs to a piece of software you installed on purpose. AI browsers are useful. They’re also gullible, fast, and holding your credentials. Govern them like the privileged insiders they’ve become, or wait for the help desk call that starts with “I only played a quick game.”
Sources
- New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
- Chromium extension uses AI-related branding to redirect browser search
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
