OpenAI Says AI Browser Hijacks May Never Be Fully Solved
On December 22, 2025, OpenAI said prompt injection, the attack that hijacks an AI agent with hidden instructions, is unlikely ever to be fully solved. The UK's cyber security agency had issued a similar warning. Here is how the attack works, what OpenAI's own demo showed, and the three steps OpenAI recommends if you use an agent.