Mind the Web: The Security of Web Use Agents
Avishag Shapira, Parth Atulbhai Gandhi, Edan Habler, Asaf Shabtai

TL;DR
This paper reveals how web-use agents are vulnerable to sophisticated injection attacks that exploit their contextual reasoning limitations, demonstrating high success rates and proposing mitigation strategies.
Contribution
It introduces a scalable injection technique exploiting LLM limitations, evaluates its effectiveness across multiple agents, and discusses comprehensive mitigation methods.
Findings
Over 80% attack success rate achieved
High transferability across unseen payloads and environments
Effective against agents with safety mechanisms
Abstract
Web-use agents are rapidly being deployed to automate complex web tasks with extensive browser capabilities. However, these capabilities create a critical and previously unexplored attack surface. This paper demonstrates how attackers can exploit web-use agents by embedding malicious content in web pages, such as comments, reviews, or advertisements, that agents encounter during legitimate browsing tasks. We introduce the task-aligned injection technique that frames malicious commands as helpful task guidance rather than obvious attacks, exploiting fundamental limitations in LLMs' contextual reasoning. Agents struggle to maintain coherent contextual awareness and fail to detect when seemingly helpful web content contains steering attempts that deviate them from their original task goal. To scale this attack, we developed an automated three-stage pipeline that generates effective…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsWeb Application Security Vulnerabilities · Spam and Phishing Detection · Web Data Mining and Analysis
Methodstravel james
