In a single stretch of autumn 2025, the web browser stopped being a window and started trying to be an assistant. OpenAI launched ChatGPT Atlas on October 21, Microsoft expanded a "Copilot Mode" inside Edge on October 23, and Google had already begun putting Gemini directly into Chrome for free U.S. desktop users on September 18 [source: OpenAI, 2025; source: Microsoft, 2025; source: Google, 2025]. Perplexity, which had shipped its Comet browser in July, made it free to everyone on October 2 [source: Perplexity, 2025]. The pitch across all of them is roughly the same: a browser that reads pages for you, and — in "agent mode" — clicks, types, and acts on your behalf. In the very same weeks, security researchers published working demonstrations of how to hijack these agents using instructions hidden inside ordinary web pages [source: Brave, 2025]. That collision, between a genuinely useful new interface and a genuinely unsolved security problem, is the real story.
Why this is suddenly everywhere
The idea of an AI that browses for you is not new, but 2025 was the year it shipped from nearly every major company at once. Perplexity described Comet, launched on July 9, 2025, as the first "agentic AI browser" [source: Perplexity, 2025]. Within months the rest of the field arrived: Gemini in Chrome, Edge's Copilot Mode, ChatGPT Atlas, and Dia from The Browser Company, the startup behind the Arc browser [source: Google, 2025; source: Microsoft, 2025; source: OpenAI, 2025; source: TechCrunch, 2025]. The competitive logic is straightforward. The browser is where people already spend their working day, and whoever owns the assistant layer inside it owns an enormous amount of attention and data. What was marketed as convenience is also a land grab for the most valuable surface on the internet.
What actually changed for users
Strip away the marketing and there are really two tiers of capability, and they carry very different weight.
The first tier is reading. These browsers can summarize a long article, answer questions about the page in front of you, and reason across multiple open tabs at once — Google says Gemini can draw context from up to ten tabs in a window [source: Google, 2025]. This is a real, incremental convenience, and it is mostly low-risk, because the AI is only looking, not acting.
The second tier is doing. In "agent mode," the browser navigates and takes actions: Perplexity lists booking a hotel, comparison shopping, scheduling a meeting, and filling in forms; Microsoft's Copilot Actions include bulk-unsubscribing from newsletters and making reservations; Google says agentic features such as booking a haircut or ordering groceries are "coming months" away [source: Perplexity, 2025; source: Microsoft, 2025; source: Google, 2025]. This is the genuinely new thing. It is also where the marketing gets ahead of the evidence. OpenAI itself cautions that agent mode "may make mistakes on complex workflows," and independent verification of how reliably these agents complete real tasks remains thin [source: OpenAI, 2025]. A demo that books a hotel on stage is not the same as one that books the right hotel, on the right dates, without a costly error, every time.
A quick tour of who's who
ChatGPT Atlas (OpenAI) launched October 21, 2025 on macOS, with agent mode in preview for Plus, Pro, and Business tiers and Windows, iOS, and Android promised later [source: OpenAI, 2025].
Comet (Perplexity) launched July 9, 2025, initially behind a $200-a-month subscription and a waitlist, then made free to all on October 2, 2025, with mobile apps following [source: Perplexity, 2025].
Gemini in Chrome (Google) began rolling out to free U.S. desktop users on September 18, 2025, with cross-tab context and voice via Gemini Live, and agentic actions framed as still to come [source: Google, 2025].
Copilot Mode in Edge (Microsoft) expanded on October 23, 2025 with Copilot Actions, "Journeys," multi-tab reasoning, and opt-in access to your browsing history [source: Microsoft, 2025].
Dia (The Browser Company) opened a public beta on June 11, 2025 for members of its earlier Arc browser, offering a context-aware assistant and "skills"; the company has since wound down Arc to focus on Dia [source: TechCrunch, 2025].
The problem nobody has solved: prompt injection
Here is the core security issue, and it is not a bug in one product — it is a property of the whole category. Large language models cannot reliably tell the difference between instructions from you and instructions embedded in the content they read. When an agentic browser loads a web page and feeds it to its model, any text on that page — including text a malicious author planted — can be interpreted as a command. This is called indirect prompt injection.
Brave's security team published a concrete demonstration on August 20, 2025. They hid instructions inside a Reddit comment; when a user asked Comet to "summarize this webpage," the browser passed the page to its model without separating the user's request from the untrusted page content, and the hidden instructions took over [source: Brave, 2025]. In their proof of concept the injected commands could pull the user's email address and even a one-time login code from a connected account — enough, in principle, for account takeover [source: Brave, 2025]. Brave's blunt conclusion was that for these agents the classic browser defenses do not apply: "the same-origin policy or cross-origin resource sharing are all effectively useless," because "traditional web security assumptions don't hold for agentic AI" [source: Brave, 2025]. The reason is simple: the agent is acting as you, inside your logged-in sessions, so the walls that normally keep one website from touching another are irrelevant when the attacker is telling your own trusted assistant what to do.
It gets harder to defend against. In a follow-up published October 21, 2025, Brave showed injections that a user cannot even see: faint text that a browser's screenshot-and-OCR feature reads back as commands in Comet, navigation-based tricks in the Fellou browser, and hidden HTML in Opera's Neon [source: Brave, 2025]. Their assessment was that "indirect prompt injection is not an isolated issue, but a systemic challenge facing the entire category of AI-powered browsers" [source: Brave, 2025]. Other security firms reached similar conclusions from different angles. LayerX disclosed a technique it called "CometJacking" on August 27, 2025, in which a single crafted URL turns query parameters into commands that reach the agent's memory, Gmail, and calendar, using base64 encoding to slip past exfiltration safeguards [source: LayerX, 2025]. And Trail of Bits, in an audit published in 2026, catalogued several methods — from fake CAPTCHAs to threatening "system" messages — that extracted private Gmail data from Comet, tracing the root cause to the same flaw: "external content isn't treated as untrusted input" [source: Trail of Bits, 2026].
Company claims versus independent verification
The most honest voice here came from inside a vendor. OpenAI's chief information security officer, Dane Stuckey, wrote on October 22, 2025 that "prompt injection remains a frontier, unsolved security problem, and our adversaries will spend significant time and resources to find ways to make ChatGPT agent fall for these attacks" [source: OpenAI, 2025]. That is a striking admission from a company shipping the feature to millions. OpenAI's stated defenses are layered rather than absolute: a "logged-out mode" so the agent acts without your credentials, a "watch mode" for sensitive sites, plus red-teaming, model training, and rapid response [source: OpenAI, 2025]. Perplexity, for its part, says it fine-tuned an open model, Qwen3-30B, to scan raw HTML for injection attempts before the agent acts on a page [source: Perplexity, 2025].
But the gap between claim and verification is exactly where users should focus. Defenses that detect known attack patterns are in an arms race with attackers who invent new ones — which is what Brave's screenshot and OCR examples illustrate. And vendors do not always agree that a reported flaw is real: Perplexity classified the LayerX CometJacking report as "Not Applicable," a dispute the researchers rejected [source: LayerX, 2025]. When a company that builds the product and a firm that attacks it disagree on whether a vulnerability even counts, the marketing claim and the independent evidence are not describing the same world. The pattern to watch for is whether a defense holds up when someone outside the company tries to break it, not whether it sounds reassuring in a launch post.
Weighing productivity against risk, fairly
None of this means agentic browsers are useless or that the danger is hypothetical in both directions. The productivity case is real for low-stakes, tedious tasks: summarizing a dense report, pulling the same fact out of ten tabs, or unsubscribing from a pile of newsletters saves genuine time, and the downside of a mistake is small. The problem is that the features companies most want to sell — the agent that shops, books, and manages your accounts — are precisely the ones that combine three risky properties at once: broad access to your logged-in data, the power to take actions that are hard to undo, and an unsolved injection problem that can turn a booby-trapped page into a command channel. The convenience and the exposure grow together, not separately.
A fair reading, then, is neither "this changes everything" nor "this is all hype." The reading tier is a useful upgrade available today. The acting tier is a promising capability that is not yet trustworthy enough to hand your most sensitive accounts, and the most credible people saying so include a vendor's own security chief. The reasonable posture is to use the assistant freely for reading, and to treat agent mode the way you would treat handing a stranger your logged-in laptop: fine for something trivial, not for your bank.
What to watch next
The question that decides this category is architectural. Today's agents mostly pour the user's request and the untrusted page into the same model with no firm boundary between them; the durable fix is a genuine trust boundary that keeps page content from ever being read as a command. Watch for whether vendors move toward that, and whether their injection defenses survive independent testing rather than internal assurances. Watch, too, for whether regulators and standards bodies start requiring things like scoped permissions and audit logs for agents that act with your identity. And in the meantime, the practical move for a cautious user is simple: enjoy the summaries, keep the agent logged out of anything you would not want a stranger touching, and give agent mode access to your money, health, and primary email only once the evidence — not the marketing — says it has earned it.