you gave the agent your browser. now the webpage gives it orders.
palo alto's unit 42 has now observed indirect prompt injection in the wild: text hidden on a page, invisible to you, read by an ai browser agent as if it came from you, while that agent is signed into your accounts. owasp's position is that this is not a bug with a patch date, it is how the architecture reads input, because the page and your instructions arrive in the same stream and nothing in the model separates them. the cost is whatever that browser profile can reach: banking, payroll, the admin panel, the inbox you reset passwords from, and the damage looks like an action you took, from your session, with logs that agree. the advice going around is to be careful which sites you let it visit, which assumes you know in advance every link it will follow three steps into a task.
do the version that holds: give the agent its own browser profile with nothing valuable logged into it, and keep banking, payroll, admin and email in a profile it never touches. then write down the short list of actions that always require a human click, money out, credentials, anything you cannot undo, and treat the agent as a very fast assistant who will believe anything it reads.