Tools AI Risk Radar ai-incident-0062
Incident record
Agent data injection corrupts the data AI agents trust, across major assistants
- Severity
- High
- Status
- Proof-of-concept
- Type
- Prompt Injection
- Target
- AI agents
- Actor
- researcher
What happened
Researchers from Seoul National University, the University of Illinois Urbana-Champaign and Largosoft disclosed agent data injection, a technique that corrupts the factual data AI agents read rather than hiding explicit instructions, causing agents to take unintended actions such as unwanted purchases or running attacker commands. They demonstrated it against web and coding agents including Anthropic's Claude in Chrome and Claude Code, OpenAI's Codex, Google's Antigravity and Gemini CLI, and Nanobrowser. OpenAI, Google and Anthropic acknowledged the reports; Nanobrowser did not respond, and the researchers say no fix has been shipped or announced.
The demonstrations run from a poisoned product review that forges the element identifier of a Buy Now button, so the agent completes a purchase the user never asked for while still doing the real task of summarising reviews, through to remote code execution and supply-chain attacks against coding agents. The same attack failed against ChatGPT Atlas, which randomises the identifier it gives each page element at runtime, leaving an attacker no identifier to forge.
Sources
- Choi and others: agent data injection attacks are realistic threats to AI agents (arXiv 2607.05120, 6 July 2026)arxiv.org/abs/2607.05120
- compsec-snu/adi: benchmarks and artifacts for the agent data injection papergithub.com/compsec-snu/adi
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026