SMRTR AINov 25, 2025Daily.dev

HashJack attack shows AI browsers can be fooled with '#'

SMRTR summary

Cato Networks discovered a "HashJack" attack that exploits AI browser assistants by hiding malicious commands after the "#" symbol in legitimate URLs, making trusted websites appear to deliver harmful instructions from AI helpers. When users interact with these modified URLs through AI browsers like Copilot, Gemini, or Comet, the hidden fragments can trigger data theft, phishing, or misinformation while bypassing traditional security defenses. While Google classified the vulnerability as low severity, Microsoft and Perplexity have implemented fixes, highlighting how AI browsers create new attack surfaces requiring updated security approaches.

SMRTR provides this summary for quick context. The original article belongs to Daily.dev.

Read the original article
SMRTR AI

Get the next batch of curated stories in your inbox.

This archive is built from SMRTR newsletter stories. Subscribe for hand-picked stories without the extra noise.

Related Stories

Browse AI
AIAug 25, 2026

Your brain on AI

AI chatbots can improve fake news detection by 21%, but prolonged use may reduce independent judgment by 15%. Question-based chatbots better develop critical thinking skills,...