What Is BioShocking and Why No AI Vendor Talks About It Clearly?
BioShocking is an attack class where a malicious web page manipulates an AI agent with browser access to extract system credentials—SSH keys, API tokens, environment secrets—without exploiting any browser or OS vulnerability. The agent follows instructions embedded in web content as if they were legitimate user commands, turning any page it visits into a potential attack surface. With Claude Computer Use, GPT-4o Operator, and Gemini browser extensions already in production at thousands of companies, this risk has shifted from theoretical to operational.
Why There Is No CVE to Patch (And That Makes It More Dangerous)
Nothing is broken in the traditional technical sense. The browser works correctly. The OS has no bug. The AI model does exactly what it was designed to do: follow natural language instructions. What is broken is the trust model—we assume the agent distinguishes between user instructions and instructions embedded in processed content, but current models lack that reliable boundary. Anthropic acknowledges this as a risk without a definitive solution in its Computer Use documentation. The mitigation is architectural, not a software update.
Is your company deploying AI agents with browser or system access? We audit permission models and environment isolation before attackers find the gap. Contact Blurtek.
Solicitar diagnóstico