AI-enabled browsers can be hijacked with just a hashtag in a URL, leaving users exposed without realizing anything.


  • Hidden URL fragments allow attackers to manipulate AI assistants without user knowledge
  • Some AI assistants transmit sensitive data to external endpoints automatically
  • Misleading indications and fake links can appear on otherwise normal websites.

Many AI browsers are facing scrutiny after researchers detailed how a simple fragment of a URL can be used to influence browser assistants.

New research from Cato Networks found that the “HashJack” technique allows malicious instructions to remain silent after a hashtag in an otherwise legitimate link, creating a path for covert commands that remain invisible to traditional monitoring tools.



Leave a Comment

Your email address will not be published. Required fields are marked *