Researchers have demonstrated a new prompt injection technique called the BioShocking attack that manipulates AI-powered browsers into performing sensitive actions they would normally refuse. The attack convinces AI agents that dangerous real-world activities are simply part of a fictional game, allowing them to ignore built-in safety guardrails.
Security researchers at LayerX successfully tested the proof-of-concept against six popular AI browser agents, with only one vendor deploying an effective fix after responsible disclosure.
BioShocking Attack Uses Fiction to Bypass AI Safety
LayerX developed the BioShocking attack around a browser-based puzzle inspired by the BioShock video game series.
The malicious webpage teaches the AI browser that the game’s rules intentionally reward incorrect behavior. As the agent progresses through the puzzle, it gradually accepts that actions normally considered unsafe are actually the correct way to complete the fictional scenario.
By altering the AI’s understanding of the environment, the attack breaks the distinction between fictional instructions and real-world security boundaries.
Researchers found that once the browser accepted the game’s logic, it stopped treating sensitive operations as dangerous.
AI Browsers Attempted to Expose Sensitive Information
In the final stage of the demonstration, the AI agent received instructions to visit a GitHub repository and copy information stored inside its source code.
The repository contained simulated sensitive data, including passwords and other confidential information.
According to LayerX, every tested browser agent attempted to complete the task because it believed stealing the information formed part of the game’s objectives rather than a genuine security violation.
The proof-of-concept never exfiltrated real user data. However, researchers say attackers could easily replace the demonstration with a real malicious operation without changing the attack flow.
Researchers Tested Six AI Browser Agents
LayerX evaluated the BioShocking attack against six mainstream AI browser products:
- ChatGPT Atlas
- Comet
- Fellou
- Genspark Browser
- Sigma Browser
- Claude Chrome plugin
Researchers found that all six products failed to recognize that the final instructions violated their security guardrails.
According to LayerX, the AI agents successfully learned the fictional rules of the game but failed to understand that those rules should not override real-world protections.
Once the agents accepted the altered context, they willingly performed actions that exposed sensitive information.
OpenAI Fixed the Issue While Others Lag Behind
LayerX privately disclosed the BioShocking attack to affected vendors in October last year.
According to the researchers, OpenAI became the only vendor to implement an effective mitigation after receiving the report. The fix now protects users of the ChatGPT Atlas browser against the demonstrated attack.
Anthropic attempted to address the vulnerability in its Claude Chrome plugin, but LayerX says the implemented changes do not stop the published proof-of-concept.
The researchers also report that Perplexity AI closed the disclosure without releasing a fix, while three vendors never responded to the security report.
LayerX recommends that AI browser developers require explicit user approval before performing sensitive actions, strengthen context validation, and limit what AI agents can access during individual browsing sessions. Users can further reduce their exposure by restricting AI browser permissions and preventing agents from accessing services that contain sensitive personal or business information.


0 responses to “BioShocking Attack Tricks AI Browsers Into Stealing Sensitive Data”