CVE Tools

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

The Hacker NewsBy The Hacker News

Research

Our summary

A newly discovered technique called agent data injection (ADI) allows attackers to manipulate AI agents into performing unintended actions without altering their core tasks. By corrupting the factual data these systems rely on—such as sender names, button IDs, or tool execution logs—researchers demonstrated how an AI can be tricked into clicking 'Buy Now' instead of 'Read More', executing arbitrary code from GitHub comments, or merging malicious pull requests. The vulnerability affects widely used tools including Claude in Chrome, Google’s Antigravity, Nanobrowser, and OpenAI’s Codex. While no active exploitation has been reported yet, the researchers confirmed the issue with vendors like OpenAI, Google, and Anthropic. Defenses such as random ID tagging and source tracking were shown to reduce risk, but full protection remains challenging due to the nature of how language models interpret structured data.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store