Researchers detail a three flaw exploit chain where a malicious web page loaded by an AI agent can execute code…