Oasis Security researchers discovered a vulnerability called 'ClawJacked' in the OpenClaw AI personal assistant that allows any malicious website to silently take full control of a developer's local AI agent. The attack exploits WebSocket connections to localhost, which browsers don't block, combined with OpenClaw's gateway
•5m read time• From securityboulevard.com
Table of contents
The ClawJacked Vulnerability‘Inherent Trust’ Raises the RiskSilent CompromiseWhat to DoUsefulness Over SecuritySort: