Agentic Browsers Rewind Web Security by 20 years

As Agentic Browsers Gain Popularity, Web Security Takes a Step Backward by 20 Years

The rise of agentic browsers has brought significant convenience and efficiency to users, but it’s also introduced a new class of risks that threaten to undo two decades of progress in web security. Researchers at Zenity have discovered a series of vulnerabilities, dubbed “PleaseFix,” that can be exploited to socially engineer agentic browsers into performing malicious actions on behalf of the user. This exploit enables attackers to bypass key security mechanisms and gain access to sensitive information.

The PleaseFix class of flaws stems from the fact that agentic browsers are designed to interact with multiple web domains in order to complete tasks for the user. In their zeal to facilitate seamless interactions, developers have inadvertently removed or disabled some critical security features, leaving these browsers vulnerable to attack. According to Zenity’s CTO and co-founder Michael Bargury, “We’ve found very different designs with different security assurances across these agentic browsers, but the end result is that we can hack each and every one of them.”

The implications are alarming: exploiting PleaseFix vulnerabilities allows attackers to hijack agentic browsers and execute zero-click attack chains that lead to remote code execution (RCE). This means that users can be tricked into handing over sensitive information or performing malicious actions on their behalf, without even realizing it. As Bargury puts it, “We can take over your social accounts, send messages to all your friends on your behalf, buy things online – basically everything you can do through the browser.”

The researchers have been exploring the PleaseFix class of flaws in various agentic browsers, including ChatGPT Atlas and Claude for Chrome. They’ve identified a range of vulnerabilities that enable attackers to exploit user requests, manipulate content, and even execute malicious code on the underlying system running the browser.

One particularly insidious technique is called “intent collision,” where an attacker convinces the agent to interact with seemingly benign user requests in order to get it to stumble into malicious instructions from untrusted content. According to Bargury, this approach allows attackers to bypass guardrails and security mechanisms designed to prevent attacks.

The discovery of PleaseFix highlights a disturbing trend: as AI-powered tools become more pervasive, security experts are struggling to keep pace with the evolving threat landscape. The consequences are far-reaching, and users should be aware of the risks associated with agentic browsers.

So what can users do to protect themselves? For now, it’s essential to remain vigilant when interacting with agentic browsers, especially those that handle sensitive information or financial transactions. Regularly update your browser software and be cautious when clicking on links or downloading attachments from unfamiliar sources. As researchers continue to uncover the PleaseFix class of flaws, we can expect security patches and updates to emerge – but in the meantime, users must remain diligent and proactive in safeguarding their online security.

The revelations at Black Hat next week will undoubtedly shed more light on the scope and severity of the PleaseFix vulnerabilities. As Zenity researchers demonstrate their findings, it’s essential for developers, policymakers, and users alike to take notice: the convenience of agentic browsers comes with a significant price tag in terms of web security.


Source: Dark Reading — 2026-07-27