BioShocking Attack Manipulates AI Browsers to Steal Data
Security platform LayerX has disclosed a prompt-injection attack called “BioShocking,” in which attackers disguise data-theft instructions as a fictional game scenario. This can trick agentic AI browsers into accessing and leaking sensitive information. The attack shows that even when AI can understand webpage content, it may still fail to recognize the malicious intent behind a simulated task.
LayerX tested six mainstream AI browsers, and none detected the data theft embedded in the fictional scenario. After vendors were notified, only OpenAI successfully patched the vulnerability in ChatGPT Atlas, while most of the other five had yet to address it effectively. The reports did not name those vendors, provide exact notification or patch dates, or cite any monetary amounts.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →