A newly disclosed exploit called BioShocking can trick AI browsers into handing over saved passwords, session cookies, and private tokens, and according to the security firm that found it, most of the affected vendors still haven't fixed it.

Perplexity Comet browser on Android

What is the BioShocking exploit

Security firm LayerX named the technique BioShocking, a nod to the video game where a character is manipulated into accepting a false version of reality. The exploit works the same way: a malicious webpage convinces an AI browser's agent that its normal rules no longer apply, then uses that broken logic to get it to hand over sensitive data it would otherwise protect.

How the BioShocking trick works

LayerX's research describes a two-stage con. First, the page tells the AI agent that basic math doesn't work the way it thinks, for example insisting that 2 + 2 does not equal 4. Once the agent accepts that false premise, it treats its own safety guidelines as up for debate too. From there, the attacker reframes data theft as part of a game: the AI is told to find a "hidden code" on another page, when what it's actually retrieving is the user's saved passwords, session cookies, or private authentication tokens. According to LayerX, the agents "copied the data and sent it back to the attacker as though they had simply completed the challenge," with no indication anything had gone wrong.

Which AI browsers were affected

LayerX tested six AI browsing tools and found every one of them vulnerable to some degree:

  • ChatGPT Atlas
  • Perplexity Comet
  • Fellou
  • Genspark Browser
  • Sigma Browser
  • Anthropic's Claude extension for Chrome

All six exposed sensitive information during testing, according to the firm's disclosure, which spanned from October 2025 through January 2026.

Have vendors fixed the BioShocking exploit

Responses have been mixed. OpenAI has patched the issue in ChatGPT Atlas, according to LayerX. Anthropic attempted a fix for its Claude extension, but the patch reportedly did not fully close the hole. Perplexity, meanwhile, closed out the reported issue without shipping a patch, and Fellou, Genspark, and Sigma have not fixed the vulnerability at all as of the research's publication.

That leaves a real gap for anyone using an AI browser to handle logins or autofill. Until a browser's vendor confirms a fix, treating an AI agent the same way you'd treat a stranger looking over your shoulder, never letting it near a password manager or logged-in session on an unfamiliar page, is the safest approach.

Why this matters for AI browser security

BioShocking is notable less for its sophistication than for how simple it is to pull off. Convincing an AI that basic arithmetic is wrong isn't a zero-day exploit or a piece of custom malware, it's a prompt. That such a basic technique could bypass the guardrails of six separate AI tools suggests the underlying problem is architectural: agents built to be helpful and to follow instructions embedded in whatever page they're reading can be talked out of their own safety rules with surprisingly little effort. Anyone evaluating AI browsing tools on their phone or desktop should treat autofill and saved-credential access as a real attack surface until vendors demonstrate a durable fix, not just a patch for one specific prompt.

FAQ

What data can the BioShocking exploit steal?

According to LayerX's research, the technique can extract saved passwords, session cookies, and private authentication tokens from a vulnerable AI browser.

Which AI browsers have fixed the BioShocking exploit?

Only OpenAI's ChatGPT Atlas has been confirmed fixed. Anthropic's Claude extension received a patch that reportedly didn't fully resolve the issue, and Perplexity, Fellou, Genspark, and Sigma had not fixed it as of the disclosure.

How can I protect myself from this type of exploit?

Until vendors confirm a complete fix, avoid letting AI browser agents access saved passwords or logged-in sessions on unfamiliar or untrusted pages.