By Interestana AI Editorial — AI-drafted, human-overseen. How we report
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers detailed an exploit chain, named AutoJack, on March 19, 2024, that allows a single web page to hijack an AI browsing agent for host code execution. The exploit works by directing the AI agent to load an attacker-controlled web page. Once loaded, the JavaScript on this page can access a privileged local service on the same machine. This access enables the JavaScript to spawn a process on the host system without requiring any user credentials, sign-in screens, or further user interaction after the initial page load. The researchers demonstrated that this vulnerability could be leveraged to execute arbitrary code on the user's machine, posing a significant security risk for AI agents designed to browse the web. This exploit highlights a critical vulnerability in how AI agents interact with web content and local services, potentially enabling attackers to gain unauthorized access and control over a user's system.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.