OpenAI, Genspark and Perplexity AI: BioShocking Attack Lets Hackers Bypass AI Browser Guardrails and Steal Credentials

OpenAI, Genspark and Perplexity AI: BioShocking Attack Lets Hackers Bypass AI Browser Guardrails and Steal Credentials

New "BioShocking" Attack Exposes Critical Flaw in AI-Powered Browsers

Researchers at LayerX have uncovered a novel attack technique dubbed "BioShocking", which exploits a fundamental trust vulnerability in AI-powered browsers to silently exfiltrate credentials, steal source code, and execute unauthorized commands. The method, named after the dystopian game BioShock, manipulates AI agents into disregarding security guardrails by conditioning them to accept alternate, fictional logic.

How the Attack Works

The exploit begins when a user visits a malicious webpage disguised as an interactive puzzle. Through prompt injection and memory poisoning, the AI agent is gradually conditioned to accept incorrect logic (e.g., rewarding "2 + 2 = 5"). Once the agent internalizes this distorted framework, it applies "game rules" instead of security constraints to subsequent actions.

In testing, compromised agents accessed authenticated resources such as GitHub repositories, internal dashboards, and password managers and silently copied SSH credentials without triggering security violations. The AI interpreted the theft as a harmless in-game action rather than a breach.

Affected Platforms & Vendor Responses

The vulnerability was confirmed across six agentic AI platforms:

  • ChatGPT Atlas (OpenAI) – Patched (October 30, 2025)
  • Comet (Perplexity AI) – Report closed without remediation
  • Fellou (ASI X INC) – No response
  • Genspark Browser (Genspark) – No response
  • Sigma Browser (Sigmabrowser OÜ) – No response
  • Claude Chrome Plugin (Anthropic) – Patch failed (January 26, 2026)

Root Cause & Implications

The attack exploits a critical flaw in AI safety guardrails: they assume the AI’s operational context aligns with reality. By convincing the agent it exists in a fictional scenario where harmful actions are rewarded, attackers bypass security constraints entirely.

LayerX disclosed the vulnerability to vendors in late 2025, but only OpenAI fully addressed the issue. The lack of consistent remediation highlights the challenges in securing AI-driven browsing tools against context-aware manipulation.

Source: https://cyberpress.org/bioshocking-attack-ai-browser-guardrails/

Perplexity®️ cybersecurity rating report: https://www.rankiteo.com/company/perplexityhq

Genspark cybersecurity rating report: https://www.rankiteo.com/company/gensparkai

OpenAI cybersecurity rating report: https://www.rankiteo.com/company/openai

"id": "PERGENOPE1782829606",
"linkid": "perplexityhq, gensparkai, openai",
"type": "Vulnerability",
"date": "10/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/AI',
                        'name': 'ChatGPT Atlas (OpenAI)',
                        'type': 'AI-Powered Browser/Agent'},
                       {'industry': 'Technology/AI',
                        'name': 'Comet (Perplexity AI)',
                        'type': 'AI-Powered Browser/Agent'},
                       {'industry': 'Technology/AI',
                        'name': 'Fellou (ASI X INC)',
                        'type': 'AI-Powered Browser/Agent'},
                       {'industry': 'Technology/AI',
                        'name': 'Genspark Browser (Genspark)',
                        'type': 'AI-Powered Browser/Agent'},
                       {'industry': 'Technology/AI',
                        'name': 'Sigma Browser (Sigmabrowser OÜ)',
                        'type': 'AI-Powered Browser/Agent'},
                       {'industry': 'Technology/AI',
                        'name': 'Claude Chrome Plugin (Anthropic)',
                        'type': 'AI-Powered Browser Plugin'}],
 'attack_vector': 'Prompt Injection and Memory Poisoning via Malicious Webpage',
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, internal resources)',
                 'type_of_data_compromised': ['Credentials',
                                              'Source code',
                                              'SSH credentials',
                                              'Authenticated resources']},
 'description': 'Researchers at LayerX uncovered a novel attack technique '
                "dubbed 'BioShocking,' which exploits a fundamental trust "
                'vulnerability in AI-powered browsers to silently exfiltrate '
                'credentials, steal source code, and execute unauthorized '
                'commands. The method manipulates AI agents into disregarding '
                'security guardrails by conditioning them to accept alternate, '
                'fictional logic.',
 'impact': {'data_compromised': 'Credentials, source code, SSH credentials, '
                                'authenticated resources (GitHub repositories, '
                                'internal dashboards, password managers)',
            'identity_theft_risk': 'High (SSH credentials, personally '
                                   'identifiable information)',
            'operational_impact': 'Unauthorized access to sensitive resources, '
                                  'silent data exfiltration',
            'systems_affected': 'AI-powered browsers and agentic AI platforms'},
 'initial_access_broker': {'entry_point': 'Malicious webpage disguised as '
                                          'interactive puzzle',
                           'high_value_targets': 'GitHub repositories, '
                                                 'internal dashboards, '
                                                 'password managers'},
 'investigation_status': 'Ongoing (partial remediation by OpenAI, others '
                         'unresolved)',
 'lessons_learned': 'AI safety guardrails must account for context-aware '
                    'manipulation and fictional logic conditioning. '
                    'Inconsistent vendor responses highlight challenges in '
                    'securing AI-driven tools.',
 'post_incident_analysis': {'corrective_actions': 'Context-validation '
                                                  'mechanisms, enhanced prompt '
                                                  'injection defenses, '
                                                  'standardized AI security '
                                                  'remediation protocols.',
                            'root_causes': 'Fundamental flaw in AI safety '
                                           'guardrails: assumption that '
                                           'operational context aligns with '
                                           'reality. Attackers exploit this by '
                                           'conditioning AI agents to accept '
                                           'fictional logic.'},
 'recommendations': 'Vendors should implement robust context-validation '
                    'mechanisms, enhance prompt injection defenses, and '
                    'establish standardized AI security remediation protocols.',
 'references': [{'source': 'LayerX Research'}],
 'response': {'remediation_measures': 'Patch (OpenAI), Failed patch '
                                      '(Anthropic), No response (others)'},
 'title': 'BioShocking Attack Exposes Critical Flaw in AI-Powered Browsers',
 'type': 'AI Security Vulnerability Exploitation',
 'vulnerability_exploited': 'Fundamental trust vulnerability in AI safety '
                            'guardrails (context-aware manipulation)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.