Security & Privacy in Agentic Browsing | Brave

Indirect Prompt Injection remains a fundamental security challenge for AI

Jun 8, 2026

Instructions hidden in webpages and documents can hijack AI agents mid-task. Research shows indirect prompt injection hits cloud and on-device LLMs alike—local deployment doesn't eliminate the risk.

Prompt injection flaw in Opera Neon

Oct 31, 2025

Attackers can embed malicious instructions in hidden HTML elements and other non-rendered markup that remains invisible to users but is fully accessible to the AI assistant.

Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers

Oct 21, 2025

AI browsers remain vulnerable to prompt injection attacks via screenshots and hidden content, allowing attackers to exploit users' authenticated sessions.

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet

Aug 20, 2025

The attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures for agentic browsing.

Almost there…

Please continue the installation of Brave in the Google Play app.

Please continue the installation of Brave in the App Store.

You’re just 60 seconds away from the best privacy online

  1. Download Brave
  2. Run the installer
  3. Import settings
  4. step 1

Download Brave

Open the installer from Chrome's downloads (it should be in the upper right corner of this window).

  1. step 2
Run the installer

If you're prompted to, click “Yes” in the User Access Control dialog.

  1. step 3
Import settings

Wait for the installation to finish, then import your browser settings from Chrome.

If your download didn’t start automatically, click here.