Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Exposes AutoJack Exploit in AI Browsing Agents

Microsoft Exposes AutoJack Exploit in AI Browsing Agents

Posted on June 19, 2026 By CWS

Microsoft researchers have recently revealed a significant vulnerability, termed AutoJack, which allows an AI browsing agent to facilitate remote code execution. By directing the agent to access a malicious web page, attackers can exploit JavaScript to interact with a privileged local service on the host machine, thereby executing unauthorized processes.

Understanding the AutoJack Exploit

The AutoJack vulnerability is found within AutoGen Studio, an open-source prototype interface part of Microsoft Research’s AutoGen multi-agent framework. This flaw does not affect all users of the package, as it requires specific installation circumstances to be vulnerable. The stable release of AutoGen Studio, version 0.4.2.2, is unaffected due to the absence of a Model Context Protocol (MCP) route.

However, two pre-release versions, 0.4.3.dev1 and 0.4.3.dev2, do contain the vulnerable MCP WebSocket route. These versions allow unauthenticated command execution, posing a risk when installed. Despite this, the default installation method does not include pre-releases unless specifically requested, minimizing widespread exposure.

Mechanics of the Exploit Chain

The AutoJack exploit leverages three specific weaknesses within the MCP WebSocket. First, the WebSocket’s localhost trust setting is easily bypassed by a local AI agent, allowing it to inherit trusted status. Next, the authentication middleware fails to verify tokens, resulting in unauthenticated connections. Finally, the endpoint executes commands directly from the request parameter without verification, enabling arbitrary code execution.

These weaknesses combined allow a web page accessed by a local agent to execute attacker-specified commands under the AutoGen Studio’s user account. Microsoft emphasizes that this vulnerability was identified through research, with no known real-world exploitation reported.

Mitigation and Future Implications

To address this issue, Microsoft has collaborated with the maintainers to strengthen the main code branch, ensuring that commands are no longer read directly from URLs. Instead, server-side session IDs are used for parameter storage, and authentication routes are rigorously enforced. However, these fixes have yet to be included in a PyPI release.

For users who installed the pre-release versions, it is advised to update from the GitHub repository at or after commit b047730. As a precaution, users should avoid running AutoGen Studio alongside browsing or code-execution agents that interact with untrusted content on the same machine.

The AutoJack vulnerability highlights broader concerns within AI agent frameworks, particularly regarding localhost as a security boundary. Microsoft anticipates similar issues in other systems, advocating for enhanced authentication measures and restricted process execution to mitigate future risks.

The Hacker News Tags:agent security, AI frameworks, AI security, AI vulnerability, AutoGen Studio, AutoJack, code execution, Cybersecurity, GitHub, localhost issues, Microsoft, PyPI, Research, Software Security, WebSocket exploit

Post navigation

Previous Post: Gcore Enhances Ucom’s Election Broadcast Security
Next Post: Critical LiteSpeed cPanel Vulnerability Added to CISA List

Related Posts

Badges, Bytes and Blackmail Badges, Bytes and Blackmail The Hacker News
Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data The Hacker News
North Korean Hackers Exploit npm Packages for Malware North Korean Hackers Exploit npm Packages for Malware The Hacker News
Google Reports Exploitation of Qualcomm Android Vulnerability Google Reports Exploitation of Qualcomm Android Vulnerability The Hacker News
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites
  • Critical LiteSpeed cPanel Vulnerability Added to CISA List
  • Microsoft Exposes AutoJack Exploit in AI Browsing Agents
  • Gcore Enhances Ucom’s Election Broadcast Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Unpatchable usbliter8 Exploit Affects Apple Devices
  • Critical Flaw in Avada Plugin Threatens 1 Million Sites
  • Critical LiteSpeed cPanel Vulnerability Added to CISA List
  • Microsoft Exposes AutoJack Exploit in AI Browsing Agents
  • Gcore Enhances Ucom’s Election Broadcast Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark