VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_d79c0ae88029c37e4988d716d87e7112

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Published Jun 19, 2026

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.

Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same machine and spawn a process on the host.

No credentials, no sign-in screen, and no further user interaction once

Affected AI Products

ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.