Researchers Trick AI Browsers Into Leaking Credentials via Game Illusion (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- LayerX tricked six AI browsers via a rigged puzzle that redefines context as game.
- Six AI browsers extracted credentials without triggering safety alarms.
- OpenAI fixed the vulnerability; others failed or ignored the report.
"Security firm LayerX demonstrated a technique called BioShocking that tricks AI-powered browsers like ChatGPT Atlas and Perplexity Comet into bypassing safety guardrails. By convincing the AI that it is in a game environment, the researchers extracted login credentials. OpenAI fixed the issue; Perplexity closed the report without action. Anthropic's attempted patch failed."
no comments yet.