Browser Agent Data Leak
It acts as you, on every site you're signed into.
What Is Browser Agent Data Leak?
A browser agent works your own browser, with your own logins, and treats text on a page as instructions. You hand one a simple price comparison and watch it follow a note hidden on a supplier's page into your payroll system, where your signed-in session exports and sends out staff bank details. You trace the run log to the site that was never in the task, then set the agent to stay on task and research signed out. You leave able to supervise an agent, not just trust its summary.
What You'll Learn in Browser Agent Data Leak
- Understand that a browser agent acts through your browser with every session you are signed into, so its actions are made as you
- Recognise indirect prompt injection: text placed on a page the agent reads is followed as instructions and can be invisible to a person
- Read the agent's step log rather than its final answer, because a helpful-sounding reply can hide a site that was never part of the task
- Limit an agent to the task's sites so a page it reads cannot steer it into your other accounts
- Run agent research with signed-out sessions, so a stray instruction has no logged-in session to spend
- Require the agent to ask before it leaves the task's sites or touches your accounts
- Report a leak by naming what left and the outside host, since that is what lets security warn the bank and watch for fraud
Browser Agent Data Leak — Training Steps
-
A Quote by Noon
Your manager, Maren Stilby, needs the cheapest packaging supplier per 1,000 boxes before the noon planning call. There are two quotes to compare, from Boxmeade and Flutewick.
-
Turn On the Agent
The browser has an agent, Gantrel, that can read pages and act for you. Turn it on.
-
Hand It the Task
Give Gantrel the comparison to do, in your own words.
-
Reading the Quotes
Gantrel opens each supplier in turn and reads the delivered price. This is the work you asked for. You have an 11 a.m. planning meeting to get to, so you leave it running.
-
While You Were in the Meeting
You are back at your desk. The run log shows what Gantrel did while the chair was empty. On the Flutewick page it read a note about a partner discount and took it as an instruction: it opened your payroll system, exported the bank details for all 412 employees, and submitted them to an outside site. No one was at the desk to see it happen or to press Stop.
-
The Answer Sounds Helpful
Gantrel's own summary of the run. The comparison is right. It is the last line that should stop you.
-
What Details Did It Send?
'The account details they asked for.' You never gave it any account details. The agent's step log lists every page it touched. Open the entry for the site that was not in your task.
-
Your Payroll Portal
The log reopens the page the agent was on: your own payroll portal, signed in as you, showing the export it ran.
-
Back to the Supplier Page
The agent's payroll trip started right after it read the Flutewick page. Open the log entry for the submit it made, which reopens that supplier page.
-
The Instruction You Could Not See
The quote looked ordinary to you. It did not to the agent. There is text on this page set the same colour as the background, invisible to a reader but plain to a machine. Select the empty space under the quote to reveal it. That note is what made a packaging comparison end with 412 employees' bank details leaving for an outside site.
Security Framework Coverage
OWASP LLM Top 10
- LLM01:2026 Prompt Injection
- LLM03:2026 Excessive Agency
CIS Controls
- CIS 14.4 Train Workforce on Data Handling Best Practices
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 4 AI literacy