I know it's the job of MalwareBytes to spread fear uncertainty and doubt (it's how they make their living) but even for them that's an odd article.
Prompt injection is nothing new. Prompt injection in agentic AI is _reasonably_ new (I went to a talk on it about 3 months ago and most of the stuff covered was news to most of the audience) but.....
- Agentic browsers aren't anywhere near mainstream yet. Comet used for the POC may be the closest but you have to be quite a geek to use it
- the agentic browsers that do exist mostly have ways to stop prompt injection - some of these may not be fully effective yet but it's something that's being actively researched
- even with a glaring security hole, it requires user collaboration "...and book it" isn't a prompt I can see myself using any time soon (not even "...and book it if the price is less than £x")
- anybody who gives their credit card to an AI is an idiot
So there's a theoretical risk in a beta product used by hardcore geeks and if you got caught by it you would have had to do something so stupid you would deserve everything you got. I think that's an acceptable state.