logo

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

ID: 1ae3d15d-8ca7-589d-9cc7-0fb96bf6b0c1

STIX ID: report--1ae3d15d-8ca7-589d-9cc7-0fb96bf6b0c1

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: [email protected] (The Hacker News)

...
...

Microsoft researchers disclosed “AutoJack,” an exploit chain that lets a local AI browsing agent open an attacker-controlled page which then abuses AutoGen Studio’s MCP WebSocket (present in two pre-release PyPI builds) to execute arbitrary commands as the AutoGen Studio user; a proof-of-concept triggers calc.exe, Microsoft reported no in-the-wild exploitation, and the maintainer patched the GitHub main branch but the fix is not yet released on PyPI—mitigations include not running AutoGen Studio alongside untrusted browsing agents or isolating them and pulling the patched source.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.