These are among the largest and most diverse set of security and privacy threats introduced by a single spec -- a malicious website can very likely access huge amounts of personal information from the user, including from other origins (all of their emails, say), other browsing history, or other sensitive sources, without any user involvement or awareness, and even take consequential actions that cost the user money, spread the harms to other people, hurt reputations, etc.
But there mostly don't seem to be any mitigations? Hopefully the implementers will share notes in real time about all the prompt injection attacks that they encounter? A few of these mitigations are aimed at site authors, but the largest threats are when the site author is the attacker.
The Privacy Working Group discussed this briefly, but the reaction was mostly that the threats are severe and that the protections seem to just be missing. I recognize that many implementers are shipping various agentic browsing tools that already suffer from many of these threats, but, this seems to provide a well-suited surface for large-scale open-ended attacks.
These are among the largest and most diverse set of security and privacy threats introduced by a single spec -- a malicious website can very likely access huge amounts of personal information from the user, including from other origins (all of their emails, say), other browsing history, or other sensitive sources, without any user involvement or awareness, and even take consequential actions that cost the user money, spread the harms to other people, hurt reputations, etc.
But there mostly don't seem to be any mitigations? Hopefully the implementers will share notes in real time about all the prompt injection attacks that they encounter? A few of these mitigations are aimed at site authors, but the largest threats are when the site author is the attacker.
The Privacy Working Group discussed this briefly, but the reaction was mostly that the threats are severe and that the protections seem to just be missing. I recognize that many implementers are shipping various agentic browsing tools that already suffer from many of these threats, but, this seems to provide a well-suited surface for large-scale open-ended attacks.