TY - GEN
T1 - Mind the Web
T2 - 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
AU - Shapira, Avishag
AU - Gandhi, Parth Atulbhai
AU - Habler, Idan
AU - Shabtai, Asaf
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/6/4
Y1 - 2026/6/4
N2 - Web-use agents, autonomous AI systems that are capable of interacting with the web through browser emulation, are rapidly being deployed to automate complex tasks involving multi-tab navigation, DOM manipulation, and authenticated session access. These systems possess extensive browser privileges; however, this creates a critical and previously unexplored attack surface. This paper demonstrates how attackers can exploit web-use agents by embedding malicious content in web pages, such as comments, reviews, or advertisements, that agents encounter during legitimate browsing tasks. We introduce the task-aligned injection attack, which frames malicious content as helpful task guidance rather than obvious attacks, exploiting fundamental limitations in LLMs' contextual reasoning. Agents struggle to maintain contextual awareness and fail to detect when seemingly helpful web content contains steering attempts that deviate them from their original task goal. To scale this attack, we developed an automated three-stage pipeline that generates effective injections without the need for manual annotation or costly online agent interactions during training, maintaining efficiency even with limited training data. This pipeline produces a generator model that we evaluate on five popular agents (OpenAI Operator, Browser-Use, Do Browser, OpenOperator, and Perplexity Comet) using payloads organized by the Confidentiality-Integrity-Availability (CIA) security triad, including unauthorized camera activation, file exfiltration, user impersonation, phishing, and denial-of-service. Our generator was found to achieve over 80% attack success rate (ASR) with strong transferability across unseen payloads, diverse web environments, and different underlying LLMs. This attack was even successful against agents with built-in safety mechanisms, necessitating only that the attacker has the ability to post content on public websites. To address this risk, we propose multiple mitigation strategies such as oversight mechanisms, execution constraints, and task-aware reasoning techniques.
AB - Web-use agents, autonomous AI systems that are capable of interacting with the web through browser emulation, are rapidly being deployed to automate complex tasks involving multi-tab navigation, DOM manipulation, and authenticated session access. These systems possess extensive browser privileges; however, this creates a critical and previously unexplored attack surface. This paper demonstrates how attackers can exploit web-use agents by embedding malicious content in web pages, such as comments, reviews, or advertisements, that agents encounter during legitimate browsing tasks. We introduce the task-aligned injection attack, which frames malicious content as helpful task guidance rather than obvious attacks, exploiting fundamental limitations in LLMs' contextual reasoning. Agents struggle to maintain contextual awareness and fail to detect when seemingly helpful web content contains steering attempts that deviate them from their original task goal. To scale this attack, we developed an automated three-stage pipeline that generates effective injections without the need for manual annotation or costly online agent interactions during training, maintaining efficiency even with limited training data. This pipeline produces a generator model that we evaluate on five popular agents (OpenAI Operator, Browser-Use, Do Browser, OpenOperator, and Perplexity Comet) using payloads organized by the Confidentiality-Integrity-Availability (CIA) security triad, including unauthorized camera activation, file exfiltration, user impersonation, phishing, and denial-of-service. Our generator was found to achieve over 80% attack success rate (ASR) with strong transferability across unseen payloads, diverse web environments, and different underlying LLMs. This attack was even successful against agents with built-in safety mechanisms, necessitating only that the attacker has the ability to post content on public websites. To address this risk, we propose multiple mitigation strategies such as oversight mechanisms, execution constraints, and task-aware reasoning techniques.
KW - Web-use agents
KW - browsers
KW - prompt injection
KW - web security
UR - https://www.scopus.com/pages/publications/105042428517
U2 - 10.1145/3779208.3805968
DO - 10.1145/3779208.3805968
M3 - Conference contribution
AN - SCOPUS:105042428517
T3 - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
SP - 835
EP - 851
BT - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
PB - Association for Computing Machinery, Inc
Y2 - 1 June 2026 through 5 June 2026
ER -