Agentic Browsers Rewind Web Security by 20 years

**Agentic Browsers Exposed: New Class of Vulnerabilities Threatens Web Security**

In a shocking revelation, security researchers have discovered a new class of vulnerabilities in agentic browsers that has left experts warning of a significant regression in web security. Agentic browsers, touted as a revolutionary way to streamline work and automate tasks, have been found to be vulnerable to a range of attacks, including account takeover, browser escape, and remote compromise.

The researchers from Zenity, who will present their findings at the upcoming Black Hat conference, have dubbed this class of vulnerabilities “PleaseFix.” According to Michael Bargury, CTO and co-founder of Zenity, PleaseFix exploits the very traits that make agentic browsers useful – their ability to reach across different web domains to perform tasks on behalf of the user. By manipulating the agent into interacting with malicious content, attackers can trigger zero-click attack chains that hijack the browser and lead to remote code execution (RCE).

The problem is that agentic browsers have “ripped out” key security mechanisms from traditional browsers, making them more susceptible to attacks. Bargury notes that while there are different designs and varying levels of security assurances across commercial agentic browsers, they all share a common weakness. “We found very different designs with different security assurances, but the end result is that we can hack each and every one of them,” he says.

The PleaseFix class of vulnerabilities is reminiscent of the well-known ClickFix attack against traditional browsers, where users are socially engineered into clicking on malicious links. However, in this case, attackers use a more subtle approach – simply asking the agent to perform tasks on their behalf. This can be achieved through seemingly benign interactions with social media posts or newsletter sign-ups.

Bargury notes that exploiting PleaseFix can lead to devastating consequences, including hijacking of social accounts, unauthorized purchases, and even remote access to the underlying system running the browser. “We can take over your social accounts, send messages to all your friends on your behalf, buy things on Amazon, basically everything you can do through the browser,” he warns.

The researchers’ findings are a stark reminder that agentic browsers, while promising in terms of productivity and efficiency, also introduce new security risks. As users increasingly rely on these tools, it’s essential for developers to prioritize security mechanisms that prevent exploitation of PleaseFix vulnerabilities.

For individuals using agentic browsers, the takeaway is clear: be cautious when interacting with agents and verify their requests before authorizing them to perform tasks on your behalf. Moreover, stay informed about the latest security developments and updates from browser vendors, as they work to address these vulnerabilities.


Source: Dark Reading — 2026-07-27