about
Security audit of Browser Use: prompt injection, credential exfil, domain bypass (arxiv.org)
2 points by tiny-automates 236 days ago | hide | past | pdf | 1 comment on HN

In plain words: They mapped every way an AI web-browsing assistant can be attacked, then dug through the code of one popular open-source tool to test those risks. Hidden instructions on ordinary web pages could hijack the agent, slip past its domain checks, and steal saved passwords — one flaw was officially confirmed with a working exploit.

Abstract · The Hidden Dangers of Browsing AI Agents

Autonomous browsing agents powered by large language models (LLMs) are increasingly used to automate web-based tasks. However, their reliance on dynamic content, tool execution, and user-provided data exposes them to a broad attack surface. This paper presents a comprehensive security evaluation of such agents, focusing on systemic vulnerabilities across multiple architectural layers. Our work outlines the first end-to-end threat model for browsing agents and provides actionable guidance for securing their deployment in real-world environments. To address discovered threats, we propose a defense in depth strategy incorporating input sanitization, planner executor isolation, formal analyzers, and session safeguards. These measures protect against both initial access and post exploitation attack vectors. Through a white box analysis of a popular open source project, Browser Use, we demonstrate how untrusted web content can hijack agent behavior and lead to critical security breaches. Our findings include prompt injection, domain validation bypass, and credential exfiltration, evidenced by a disclosed CVE and a working proof of concept exploit.

Mykyta Mudryi, Markiyan Chaklosh, Grzegorz Wójcik
arXiv:2505.13076 · cs.CR, cs.AI · submitted May 19, 2025
abstract · pdf · html

add comment on HN
Also discussed: May 2025 (2 points, 0 comments) · May 2025 (2 points, 0 comments)

the planner-executor isolation point is what stood out to me. right now most browser agent frameworks treat the LLM as both the decision-maker and the one processing untrusted content — so a prompt injection in page content can hijack the entire control flow.

the paper's recommendation to split planning (trusted inputs only) from execution (handles untrusted web content) mirrors how we think about privilege separation in OS design, but almost nobody building agent frameworks is actually doing it.

the CVE they found is also telling — Browser Use's domain allowlist could be bypassed, which means the "security" feature was essentially decorative. When you give an agent session tokens and let it navigate freely, the trust boundary problem isn't optional anymore.