AI web browsers bypass same-origin policy, researchers warn April 26
Agentic browsers add chatbot power fast, but scientists say security got worse, not better, for user data.

Scientists from a new study warned that popular agentic AI web browsers are bypassing the same-origin policy that protects users’ private data. The findings were presented April 26 at the Agents in the Wild Workshop in Rio de Janeiro, Brazil.
An assistant professor at the University of Washington just delivered a blunt verdict on agentic AI web browsers: they are not ready for the public. In research presented April 26 at the Agents in the Wild Workshop in Rio de Janeiro, Brazil, co-author David Kohlbrenner warned that even savvy users should not trust these systems to truly protect information when the agent has access to browser credentials like email and bank details.
The reason is specific and technical, but the risk is painfully practical. Conventional browsers rely on the “same-origin policy” to stop different websites from interacting in ways that could leak data. The researchers found that many popular AI browsers do not preserve that separation, potentially allowing malicious cross-origin content to reach the agent and trigger unsafe behavior.
So what are “agentic browsers,” and why are they moving so quickly? These browsers look like ordinary internet browsers, but with AI agent functionality baked in. Using AI, they can summarize websites, search for specific information, and automate repetitive tasks. The appeal is obvious: instead of manually browsing a webstore, comparing items, and making a purchase, a person can use an AI browser to do more of the work end-to-end. Many agentic browsers have only been released in 2025, and they are already rising in popularity.
But the study argues that enhancing functionality can quietly degrade security. The same-origin policy is one of the long-standing protections in web browsing. It prevents sites from “talking” to each other while a user has multiple tabs open, which helps stop malicious code on one site from spilling into another. For example, if a bank site is open in one tab and a webpage with malicious code is open in another, the same-origin policy blocks interaction between the two.
AI browsers, however, often need broader access to web content to be useful. The researchers explain that AI browsers require full access to all web content available to the user. That can include cross-origin iframes, such as code shared across multiple websites (including online advertisements), or it can require cross-origin visibility to access information from multiple sites. In other words, the agent is trying to see more of the page landscape than a conventional browser typically allows to interact safely.
This is where the security red flags become concrete. One major risk highlighted is “prompt injection,” where an AI agent is tricked into misinterpreting data embedded on a malicious website as instructions it should carry out. In the study’s example, an AI browser visits an otherwise “safe” website, but malicious code embedded within it contains a hidden instruction that could prompt the agent to automatically share the user’s personal details.
Another risk is “memory poisoning.” Here, the agent stores information it processes in its memory for future use, and that stored information can become a target. The study says some agents mingle information from different origins, likely because they were revising and compressing their memory. That is a second-order problem that matters for product teams: the browser agent is not just a renderer, it is a stateful system that can carry compromised context forward.
The researchers didn’t make a theoretical argument only. They examined seven browsers: Atlas, Claude for Chrome, Brave Leo AI, Chrome with Gemini, Microsoft Edge with CoPilot, Firefox AI Mode, and Perplexity Comet. They used test sites and prompts to study how each behaved, focusing on the information an agent could access from same-origin and cross-origin webpages, the actions each agentic browser could take, and the agent’s chat context and history. The results: there is “no consistency among AI browsers” in how they operate, which the researchers suggest could stem from a lack of standardization in how AI browsers interact with browser security.
The study also found that some browsers could freely access cross-origin frame content while others restrict access. Some can simultaneously access multiple tabs, but most require permission from the user. Some agents can take actions directly on a page based on instructions embedded in webpages; others cannot take actions at all. In short, the security posture is not uniform across the category, which complicates both buyer decisions and board-level risk assessment.
Based on those differences, the researchers advised users to be careful because a standardized security model for these systems has not been developed. They were particularly cautious about Claude for Chrome for its strong capabilities, as well as Atlas and Comet, which have similarly strong functionality. By contrast, they identified Brave as stronger in security due to limited agentic features, and they also pointed to agentic versions of Edge and Firefox as having stronger security because of limited agentic behavior.
For executives and investors, the business tension is the whole story. The study notes that currently, the more functional an AI browser is, the less secure it becomes, at least under today’s trade-offs. The researchers also say companies are pushing out these browsers under competitive pressure. That raises a governance question: when product speed is the strategy, how do you avoid turning security into an afterthought, especially when the underlying web security model was designed and refined over decades?
The quote that lands hardest is the “big step back” framing. After 30 years of building up the same-origin policy, the researchers argue that AI agent integration is taking browser security backward. Looking forward, they question how to integrate AI agents into browsers in ways that preserve rich functionality without undermining security and exposing sensitive information. That is the strategic stake for anyone building, buying, or backing “agentic” experiences right now: the next competitive leap will not be measured only by convenience. It will also be measured by whether these systems can keep user data compartmentalized while doing more of the internet on your behalf.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Science
UK teams develop a core HWO instrument for NASA’s Habitable Worlds Observatory launch in the 2040s
The next flagship after the Nancy Grace Roman Space Telescope is coming in the 2040s, and UK hardware work is already in the critical path.
University of Tokyo boosts cancer-relevant vesicle capture with metal-ion coating
Researchers use metal ions to strengthen cell-vesicle sticking, improving detection and targeted delivery even amid massive vesicle mixtures.

Cambridge professor transcribes Alan Turing's last-year story, adding a new side
The newly transcribed handwritten story, written in the year before his death, reshapes how leaders understand Turing's legacy.

