{
  "slug": "agentic-browser-sessions",
  "title": "Your agentic browser is logged into your bank. What stops a web page from moving the money?",
  "summary": "Agentic browsers act inside your live logged in sessions. A malicious page can drive one into your bank. Only an out of band signature stops it.",
  "lede": "An agentic browser does not have its own credentials. It drives yours, inside every session you are already logged into, and it cannot reliably tell your instructions apart from text it reads on a page. That combination turns a hidden paragraph in an email into an instruction to move your money.",
  "date": "2026-09-05",
  "reading_time": "14 min read",
  "category": "Agents",
  "tags": [
    "agentic browser",
    "prompt injection",
    "AI agents",
    "session security",
    "payment authorization",
    "banking security"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Agentic%20Browser%20Risk/1200_630/blog.jpg",
  "url": "/blog/agentic-browser-sessions.html",
  "wordcount": 4071,
  "related": [
    "session-theft-aitm",
    "prove-agent-authorized",
    "identity-failure-map"
  ],
  "schema": "Article"
}