Microsoft Warns AI Agents Are Being ‘AutoJacked’ To Deliver RCE Payloads By Browsing Untrusted Sites


  • Microsoft’s Defender Security Research Team Reveals “AutoJack”, a Chain of Vulnerability in AutoGen Studio That Enables RCE Via Malicious Websites
  • The flaws included local host channel abuse, skipped login checks, and arbitrary code execution, which allowed agents to run attacker-delivered programs
  • The issue only existed in early GitHub builds, fixed before release; highlights the need for strict authentication and isolation of local control planes

Microsoft’s Defender Security Research Team has uncovered a vulnerability chain in AutoGen Studio that lets a single malicious website achieve remote code execution (RCE) on a device running an AI agent.

AutoGen Studio is a program built by Microsoft Research for developing AI agents. Dubbed “AutoJack,” the chain of vulnerabilities consists of three flaws that, when viewed separately, are not particularly worrisome. Chained together, however, is a completely different story.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top