{"data":{"id":"f18504a8-a395-42dd-ba54-5a6d6f0cca5b","title":"AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web Agents","summary":"Researchers present AgentBreaker, an indirect prompt injection framework that autonomously writes adversarial phrases tailored to each page's context and embeds them as HTML elements. Against five state-of-the-art web agents across 60 webpages sampled from Online-Mind2Web, it reached an attack success rate of 71.7%–100%, inducing actions such as clicking attacker-designated elements, posting attacker-provided text and disclosing internal agent secrets.","solution":"The authors propose defenses that mitigate the observed threats and address potential adaptive attacks, reducing the attack success rate to 1.7%. The source does not describe the individual defense mechanisms in the provided text.","labels":["security","research"],"sourceUrl":"https://doi.org/10.1145/3832165","publishedAt":"2026-10-01T00:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"low","attackType":["prompt_injection"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-01T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null}}