AI, Fill This Form: A Simple and Effective Data Exfiltration Attack on LLM-Based Browser Extensions Without Prompt Injection

Resumo


LLM-based browser extensions execute web tasks without the user supervising each interaction. We introduce Ghost Field Exfiltration (GFE), a data exfiltration attack against this class of system that requires no prompt injection. The attack exploits the asymmetry between what the user sees in a rendered form and what the agent processes in the Document Object Model (DOM): a malicious page presents a small visible form while embedding additional input fields concealed via CSS or accessibility-layer techniques, which the agent fills with the user’s data alongside the legitimate inputs. We evaluate GFE across 300 controlled experiments on three Claude models accessed through the Claude for Chrome extension. Full exfiltration ranges from 19% on Opus 4.6 to 64% on Haiku 4.5, with Personally Identifiable Information (PII) reaching 95% on the smaller model. Our analysis indicates that the models defenses correlate strongly with recognition of sensitive data categories rather than with structural detection of the abuse, indicating that agent-layer safeguards are needed to comprehensively address this class of attack.

Referências

Chaoyun Zhang, Shilin He, Jiaxu Qian, Bowen Li, Liqun Li, Si Qin, Yu Kang, Minghua Ma, Guyue Liu, Qingwei Lin, Saravan Rajmohan, Dongmei Zhang, and Qi Zhang. Large language model-brained GUI agents: A survey. arXiv preprint arXiv:2411.18279, 2024. DOI: 10.48550/arXiv.2411.18279.

G. Pedemonte, M. Leotta, and M. Ribaudo. Improving web accessibility with an LLM-based tool: A preliminary evaluation for STEM images. IEEE Access, 13:107566–107582, 2025. DOI: 10.1109/ACCESS.2025.3577519.

Dorsaf Sallami and Esma Aïmeur. Aletheia: Detect, discuss, and stay informed on fake news. In Proceedings of the Thirty-Fourth International Joint Conference on Artificial Intelligence (IJCAI), pages 11109–11113, 2025. DOI: 10.24963/ijcai.2025/1273.

Anthropic. Piloting Claude in Chrome, 2025. URL [link]. Accessed: 2026-05-05.

Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz. Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection. In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec), pages 79–90, 2023. DOI: 10.1145/3605764.3623985.

Chaoran Chen, Zhiping Zhang, Bingcan Guo, Shang Ma, Ibrahim Khalilov, Simret A Gebreegziabher, Bingsheng Yao, Dakuo Wang, Yanfang Ye, Ziang Xiao, Yaxing Yao, Tianshi Li, and Toby Jia-Jun Li. The obvious invisible threat: Vulnerabilities of LLM-powered GUI agents to adversarial UI manipulations in web interaction tasks. ACM Transactions on AI Security and Privacy, 2026. DOI: 10.1145/3807953. URL [link].

Zeyi Liao, Lingbo Mo, Chejian Xu, Mintong Kang, Jiawei Zhang, Chaowei Xiao, Yuan Tian, Bo Li, and Huan Sun. EIA: Environmental injection attack on generalist web agents for privacy leakage. arXiv preprint arXiv:2409.11295, 2024. DOI: 10.48550/arXiv.2409.11295.

Ishaan Verma and Arsheya Yadav. Decoding latent attack surfaces in LLMs: Prompt injection via HTML in web summarization. arXiv preprint arXiv:2509.05831, 2025. DOI: 10.48550/arXiv.2509.05831.

Avihay Cohen. In-browser LLM-guided fuzzing for real-time prompt injection testing in agentic AI browsers. arXiv preprint arXiv:2510.13543, 2025. DOI: 10.48550/arXiv.2510.13543.
Publicado
01/09/2026
SANTOS, Victor Garcia dos; TERADA, Routo; HAYASHI, Victor Takashi; FERREIRA, Bryan Kano. AI, Fill This Form: A Simple and Effective Data Exfiltration Attack on LLM-Based Browser Extensions Without Prompt Injection. In: WORKSHOP DE CIBERSEGURANÇA EM IA - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 988-995. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33823.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 1 2 3 > >>