Skip to content
Computing Life · Share · Yage

Where the agent's browser lives: the war over keeping credentials on-device

From May to August 2026, four standalone AI browsers shut down, and agent browsing retreated into existing surfaces like Chrome, Edge, and ChatGPT. The real question became: where does the page render, and whose trust boundary holds the credentials. Nine vendors line up on a spectrum—Edge, Chrome auto browse, and Perplexity Comet keep both browser and credentials local; Cowork runs tasks in the cloud but renders the browser in the local desktop app; ChatGPT Work, Devin, Manus, and Grok Bot move the browser and logins to the cloud, with Grok Bot letting all bots on one account share a single cloud computer's session. But University of Washington research punctures the illusion: even when credentials stay local, the agent reads rendered pixels, so the same-origin policy doesn't constrain it—a cross-origin iframe showing a logged-in bank page can still be exfiltrated via prompt injection. No one is truly safe yet.

Why it matters: After four standalone AI browsers shut down, the engineering divergence in agent browsing surfaces. The author lines up nine vendors along a spectrum of rendering location and credential trust boundaries — a clear comparative framework. Score isn't higher because the excerpt o...

Read the original ↗Export Markdown