Cato Networks says it has discovered a new attack, dubbed "HashJack," that hides malicious prompts after the "#" in legitimate URLs, tricking AI browser assistants into executing them while dodging traditional network and server-side defenses. Prompt injection occurs when something causes text that the user didn't write to become commands for an AI bot. Direct prompt injection happens when unwanted text gets entered at the point of prompt input, while indirect injection happens when content, such as a web page or PDF that the bot has been asked to summarize, contains hidden commands that AI then follows as if the user had entered them. AI browsers, a relatively new type of web browser that uses AI to try and guess user intent and take autonomous actions, have so far proven to be particularly vulnerable to indirect prompt injection – in their quest to be helpful, they sometimes end up helping attackers rather than end users. Cato describes HashJack as "the first known indirect prompt injection that can weaponize any legitimate website to manipulate AI browser assistants." It outlines a method where actors sneak malicious instructions into the fragment part of legitimate URLs, which are then processed by AI browser assistants such as Copilot in Edge, Gemini in Chrome, and Comet from Perplexity AI. Because URL fragments never leave the AI browser, traditional network and server defenses cannot see them, turning legitimate websites into attack vectors. The new technique works by ...
HashJack attack shows AI browsers can be fooled with a simple ‘#’
The Register
·Carly Page
·Published Nov 25, 2025
·Updated
Affected Software
1 affected component
Cato Networks AI Browser
Frequently Asked Questions
1
What is the main topic of this article?
The main topic of the article is the new HashJack attack that exploits AI browsers by manipulating URLs with a hashtag.
2
What security implications are discussed?
The article discusses how the HashJack attack allows malicious prompts to bypass security measures by tricking AI browser assistants into executing hidden commands.
3
What products or software are affected?
The affected product mentioned is the Cato Networks AI Browser.
4
How does the HashJack attack work?
The HashJack attack works by hiding malicious prompts after the '#' symbol in legitimate URLs to deceive AI browsers.
5
Who discovered the HashJack attack?
Cato Networks is credited with discovering the HashJack attack.