
What is the Microsoft AutoJack Vulnerability- What You Need to Know
On June 18, 2026, Microsoft disclosed AutoJack: a proof-of-concept exploit chain where a single malicious webpage causes an AI browsing agent to execute arbitrary code on the host machine. No credentials stolen. No malware installed. Just one page, one agent, and a localhost MCP server with no authentication. Here is everything you need to know.


















