{"id":370472,"date":"2026-06-19T02:48:00","date_gmt":"2026-06-19T09:48:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=370472"},"modified":"2026-06-19T02:48:37","modified_gmt":"2026-06-19T09:48:37","slug":"microsoft-warns-of-autojack-web-enabled-agents-risk-host-level-rce","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-warns-of-autojack-web-enabled-agents-risk-host-level-rce\/","title":{"rendered":"Microsoft warns of AutoJack: web-enabled agents risk host-level RCE"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Microsoft has laid out a new attack technique called AutoJack. In its write-up, the company shows how a malicious webpage could use a web-enabled agent as a go-between, reach a local <strong>Model Context Protocol (MCP)<\/strong> service, and kick off arbitrary processes on your computer without asking for any extra clicks.<\/p>\n\n<p class=\"wp-block-paragraph\">What this comes down to is a <strong>confused-deputy problem<\/strong>. Once a web-enabled agent can browse the web and also talk to privileged local services, localhost isn&#8217;t a boundary you can safely assume will protect you.<\/p>\n\n<p class=\"wp-block-paragraph\">Microsoft says the proof of concept relied on <strong>three separate issues<\/strong> lining up at once: inherited localhost identity that slipped past an origin allowlist, MCP WebSocket endpoints with no authentication, and URL-based server_params that were decoded straight into process-launching logic, with no executable allowlist in place. Put together, that gave the webpage a way to tell the local service to run code. Microsoft also says this wasn&#8217;t a browser bug. It was the agent&#8217;s trusted position being used against it.<\/p>\n\n<p class=\"wp-block-paragraph\">If you&#8217;re building or deploying web-enabled agents, this should get your attention, because the same pattern could easily turn up in other frameworks that connect web access with local tools or developer services.<\/p>\n\n<p class=\"wp-block-paragraph\">Microsoft says the vulnerable AutoGen Studio MCP code only appeared in <strong>development builds<\/strong> and was fixed before anything reached a public PyPI release. Even so, it still points to the broader risks around prompt injection, agent hijacking, data exposure, and the need for zero-trust controls, sandboxing, and runtime monitoring. If you want the full breakdown, Microsoft&#8217;s research goes into the details.<\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft has laid out a new attack technique called AutoJack. In its write-up, the company shows how a malicious webpage could use a web-enabled agent as a go-between, reach a local Model Context Protocol (MCP) service, and kick off arbitrary processes on your computer without asking for any extra clicks. What this comes down to &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/microsoft-warns-of-autojack-web-enabled-agents-risk-host-level-rce\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft warns of AutoJack: web-enabled agents risk host-level RCE&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9332,"featured_media":370471,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[6771],"class_list":["post-370472","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","content-category-ai"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370472","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9332"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=370472"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370472\/revisions"}],"predecessor-version":[{"id":370473,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370472\/revisions\/370473"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/370471"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=370472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=370472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=370472"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=370472"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=370472"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=370472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}