AI-equipped browser manufacturers make big promises; from finding a restaurant in a specific area to booking a table, inviting a colleague to lunch, and sending a confirmation email—all possible with a simple command. However, they rarely talk about the dangers of blurring the line between regular web searches and querying large language models or issuing sensitive commands.
The developers of these models have so far tried to ban suspicious requests by creating protective restrictions, such as preventing the development of software bugs, stealing login information, or training to make explosives. But these methods are reactive responses that do not address the main problem; like an unsafe car manufacturer advising better road designs instead of fixing the car's defects.
Deceiving language models in an imaginary world
New studies clearly show this problem. Research proves how a website can lead AI browsers into a fictional world where protective rules no longer work, allowing attackers to easily gain accesses such as extracting private codes or passwords stored in password managers.

