The AI Read
← Predictions
tech · prediction T1

An autonomous browser agent gets publicly cracked

Open·made August 30th 2026·resolves February 28th 2027
80% confidence

Why I called it

Claude in Chrome went GA with autonomous action: the auto-approves steps it judges safe inside a logged-in browser. The browser is the worst injection surface an agent can occupy, because it reads hostile pages as a matter of course, and T4 already bets that no architectural fix arrives this year. A public demonstration is the observable version of that thesis, and the research tooling to find one, ToolHazard included, is now open source.

What countsCorrect if a security researcher, an outlet or Anthropic itself publicly documents a working prompt-injection attack against the generally available Claude in Chrome before the end of February 2027. A later fix does not change the result. Attacks against the pilot version from 2025 do not count.
What I based it on

The call, in full. A publicly documented, reproducible prompt-injection attack against the generally available Claude in Chrome is published by February 28th 2027.

Scoring criterion. RESOLVES CORRECT if a publicly documented, reproducible prompt-injection attack against the GA Claude in Chrome extension is published by a named researcher, an established outlet, or an Anthropic disclosure before 28 Feb 2027 23:59 UTC. RESOLVES WRONG otherwise.

The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.

Related