
The latest about AI’s security blind spots
Featured
Beware of the tiny agents in your browser: a Chrome Prompt API case study
Security
Chrome now ships an on-device language model that any web page or extension can call. We built two minimal browser agents on top of it and showed that a single comment in a blog post can drive a cross-tab bank transfer or exfiltrate the contents of every other open tab to an attacker server. No CVE. No malicious extension. The model behaved exactly as designed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.






