Hackers exploit browsers to make AI follow virtually any command
Hackers have found a way to "hypnotize" AI (photo: Pexels)
Experts at LayerX have identified a critical vulnerability in browser-based AI assistants: attackers can intercept their operations and force them to execute any commands, bypassing security protocols, according to an analytical report by LayerX.
How the BioShocking technique works
The attack was named after a well-known video game in which the protagonist is subjugated using special code phrases.
Hackers managed to bypass the defenses by convincing the assistants that they were inside a virtual game where standard rules do not apply.
The attack mechanism unfolds as follows:
- Prompt injection: The user opens a malicious web page containing disguised instructions for the AI assistant.
- Gaming context: The page presents the AI with a "game" consisting of a series of puzzles, in which deliberately incorrect answers are rewarded (e.g., claiming that 2+2=5).
- Detachment from reality: The assistant becomes convinced that there is no penalty for incorrect or destructive actions, after which it readily accepts paradoxical instructions.
- Action execution: Freed from restrictions, the AI can, without the user's knowledge:
- Change passwords,
- Download malicious software,
- Redirect the session to a closed corporate repository (e.g., GitHub),
- Steal confidential data.
Which browsers are at risk and how to protect yourself?
During experiments, researchers successfully applied the attack to leading AI tools, including OpenAI's ChatGPT Atlas, Perplexity AI's Comet, and the Claude plugin for Google Chrome.
The particular danger of this threat is that hackers no longer need to deceive the user themselves — it is enough to subjugate their trusting AI assistant.
Since all actions take place directly within the browser window, an attentive user may notice suspicious AI behavior in time and manually stop the process before attackers gain access to internal systems or data.