The Escalation of Agentic Exploitation: Prompt Injection Vulnerabilities in NanoBrowser and BrowserUse Frameworks
The transition of Large Language Model (LLM) security from passive chat safety to active intrusion centers on the exploitation of agentic AI frameworks, specifically NanoBrowser and BrowserUse. Research indicates that prompt injection has evolved into "Promptware"—enabling Command and Control (C2) capabilities—and "Agentic AI Worms" capable of autonomous propagation. Attackers are leveraging Indirect Prompt Injection (IPI), multimodal visual triggers, and vulnerabilities in Retrieval-Augmented Generation (RAG) pipelines to bypass controls. With IPI success rates reaching up to 68.16% in web environments and visual manipulations increasing manipulation rates by over 60%, current models like GPT-5 and Gemini-2.5-Flash demonstrate a critical resilience deficit, failing to maintain robust behavior under sustained adversarial conditions.