Security & Privacy in Agentic Browsing | Brave
Indirect Prompt Injection remains a fundamental security challenge for AI
Jun 8, 2026
Instructions hidden in webpages and documents can hijack AI agents mid-task. Research shows indirect prompt injection hits cloud and on-device LLMs alike—local deployment doesn't eliminate the risk.
Prompt injection flaw in Opera Neon
Oct 31, 2025
Attackers can embed malicious instructions in hidden HTML elements and other non-rendered markup that remains invisible to users but is fully accessible to the AI assistant.
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers
Oct 21, 2025
AI browsers remain vulnerable to prompt injection attacks via screenshots and hidden content, allowing attackers to exploit users' authenticated sessions.
Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
Aug 20, 2025
The attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures for agentic browsing.
Almost there…
Please continue the installation of Brave in the Google Play app.
Please continue the installation of Brave in the App Store.
You’re just 60 seconds away from the best privacy online
Download Brave
Run the installer
Import settings
step 1
Download Brave
Open the installer from Chrome's downloads (it should be in the upper right corner of this window).
- step 2
Run the installer
If you're prompted to, click “Yes” in the User Access Control dialog.
- step 3
Import settings
Wait for the installation to finish, then import your browser settings from Chrome.
If your download didn’t start automatically, click here.