AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain named AutoJack that turns an AI browsing agent into a delivery vehicle for remote code execution Steer the agent to load an attackers web page and that pages JavaScript can reach a privileged local service on the same machine and spawn a process on the host No credentials no signin screen and no further user interaction once