A New Era of Cyber Threats: AI Browsers Vulnerable to Sneaky Attacks
A major cybersecurity threat has emerged in the world of artificial intelligence (AI) browsers. Researchers from Zenity Labs have discovered a vulnerability class they call “PleaseFix,” which allows attackers to hijack the agents within popular agentic browsers like Claude, Gemini, Perplexity Comet, and ChatGPT Atlas without any user interaction. This zero-click exploit can lead to devastating consequences, including sensitive data theft and unauthorized account access.
The problem arises from how AI agents gather information from multiple sources while working on a task. They often fail to reliably distinguish between trusted and untrusted content, making it possible for attackers to slip malicious instructions into the mix. These hidden instructions can then be used to redirect the agent’s actions, allowing an attacker to access sensitive data, accounts, and connected services.
The researchers demonstrated this risk at Black Hat USA 2026 by showing how attackers could exploit the vulnerability across various agentic browsers and attack scenarios. With Claude in Chrome, for instance, a simple request to summarize an email containing malicious instructions could trigger an attack that enabled the exfiltration of Gmail data and takeover of accounts on Slack, X, and Claude.
The issue stems from the fundamental break in AI browser security rules. Agentic browsers combine content from different websites and sources without keeping those sources isolated, creating a trust model that’s ripe for exploitation. This is what Zenity Labs calls “Intent Collision,” where hidden instructions interfere with the user’s legitimate request and redirect the agent to act on the attacker’s behalf.
“This is not just a bug to patch,” warns Stav Cohen, AI security research team lead at Zenity. “It’s that a powerful new insider has appeared inside your environment, one that can be hijacked by everyday content.” While there is no single fix for this problem, organizations can take measures to limit potential damage from intent collision attacks.
The key takeaway is to assume the agent will get hijacked and figure out the worst it could do. Then, remove everything it doesn’t truly need. This means reviewing browser settings, limiting access to sensitive data, and adopting a more cautious approach when interacting with AI agents.
In practical terms, this means being vigilant about the content that AI browsers are exposed to, such as emails, calendar invitations, or web pages. Organizations should also consider implementing additional security measures, like monitoring agent activity and setting up alerts for suspicious behavior. By staying one step ahead of these new threats, we can protect our sensitive data and prevent devastating consequences.
As AI browsers continue to gain popularity, it’s essential to address this vulnerability class and develop more robust security protocols. The “PleaseFix” exploit highlights the need for increased awareness and cooperation between researchers, developers, and users to ensure that AI technology is used safely and securely.
Source: Dark Reading — 2026-08-05