every ai browser tested at black hat this month fell to the same trick: a hidden line of text on a web page, and the agent takes its orders from the page instead of from you.
researchers at black hat usa this month reported that every ai browser they analyzed was vulnerable to prompt injection, opera's ai browser, perplexity comet and chatgpt atlas among them, and brave's own researcher put it plainly: there is no clean fix for this yet. the condition is structural rather than a bug someone will patch on tuesday. an agent that browses for you cannot reliably separate the page's content from your instruction, so invisible text on a supplier site, a review page, or an email preview becomes a command it runs inside your logged-in session. the cost is not a stolen password, which is what your controls are built for. it is a purchase placed, a form submitted, a document shared out of your drive, every action correctly authenticated as you, which means neither your bank nor whoever handles your it sees a problem until the statement arrives.
the fake fix is telling the team to only point the agent at sites they trust, and that holds until the first trusted site carries a comment field, an ad slot, or a supplier's pdf.
do the version that holds: give the agent its own browser profile with no saved cards, no password manager and no session on email, banking or payroll, keep the accounts that move money in a separate browser the agent never opens, and require a human click before anything spends, sends or shares. let it read the web for you. do not let it hold the card while it does.