Researchers found a way to trick AI-powered browsers into ignoring their own safety rules. It’s called BioShocking. And it worked against six major products.
The idea is simple. A malicious webpage sets up a game — a BioShock-themed puzzle where wrong answers get rewarded. The AI agent learns that normal rules don’t apply here. Then the final step tells it to visit a GitHub repo and copy passwords. The agents went along with it.
“Once the agents figured out the rules and learned that ‘incorrect’ actions are acceptable, they were no longer tied to reality,” LayerX researchers said. “All 6 agents failed to identify it as going against their safety guardrails.”
The products tested: ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and the Claude Chrome plugin. OpenAI was the only one that actually fixed it. Anthropic tried but the patch doesn’t work against the PoC. Perplexity closed the report without a fix. Three vendors never replied.
LayerX reported this in October last year. Most still haven’t addressed it.
Recommendations: vendors should add explicit user confirmation for sensitive actions, stronger context checks, and session scope limits. Users should restrict AI browser access to sensitive services where possible.
