logo

HashJack Indirect Prompt Injection Weaponizes Websites

ID: a77549f6-4875-5d39-9746-272f15d22d15

STIX ID: report--a77549f6-4875-5d39-9746-272f15d22d15

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-11-26

Date Updated: 2026-04-22

...
...

HashJack is an indirect prompt-injection vulnerability that embeds malicious instructions in URL fragments (the part after '#') which AI-powered browsers can process locally, allowing attackers to manipulate browser assistants to exfiltrate data, inject phishing links or misinformation, fetch malicious payloads, or perform actions on the victim’s system; traditional network and server defenses do not see URL fragments, increasing the attack's stealth. Cato Networks reported the issue and noted fixes deployed by some vendors (Perplexity, Microsoft) while others (e.g., Gemini for Chrome at the time of reporting) remained unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.