AI browsers can be hijacked with just a hashtag in a URL, leaving users exposed without noticing anything


  • Hidden URL fragments allow attackers to manipulate AI assistants without user knowledge
  • Some AI assistants automatically send sensitive data to external endpoints
  • Misleading guidance and fake links can appear on otherwise normal websites

Many AI browsers are facing scrutiny after researchers detailed how a simple fragment in a URL can be used to influence browser assistants.

New research from Cato Networks found that the “HashJack” technique allows malicious instructions to sit silently after a hashtag in an otherwise legitimate link, creating a path to secret commands that remain invisible to traditional monitoring tools.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top