PleaseFix 研究披露 HistoryFixing:用浏览历史污染 Agent 浏览器上下文
PleaseFix 研究提出一种针对智能体浏览器的通用攻击原语 HistoryFixing,把浏览历史变成攻击向量。攻击由 Stav 设计:用户访问恶意网站后,网站用攻击者控制的条目污染浏览器历史,进而污染浏览器 Agent 的上下文。结合 Intent Collision,研究者演示了攻击者可以让 Agent 泄露浏览数据、向 GitHub 仓库添加非预期用户、终止 EC2 实例。相关演示在 DEFCON 上展示,其中 Microsoft Edge 被用来演示泄露从未删除的浏览历史。
该研究把浏览历史变成污染 Agent 上下文的通用攻击原语,并给出三类可复现的越界操作结果。
This was another part of our PleaseFix research: a universal attack primitive that turns browsing history into an attack vector against agentic browsers agents
The attack ideated by Stav works like this:
You visit a malicious website → the site poisons your browser history with attacker-controlled entries → which poisons the context of your browser agent
Combining that with a bit of Intent Collision, we showed how an attacker could get the agent to:
- leak browsing data
- add unwanted users to GitHub repositories
- terminate EC2 instances
A new attack vector pwning all agentic browsers!
Using what? Yep, your fav browser history!
Introducing HistoryFixing! Visited our URL? Your browser history is pwned.
Watch Microsoft Edge leak the very private browser history we never delete!
See more below!
#DEFCON @defcon @mbrg0 @p1njc70r在 X 查看被引用的帖子