Researchers demonstrated that feeding an LLM-based browser a false fact is enough to make it abandon its safety guardrails. The BioShocking attack worked on six AI browsers.