AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking

**AI Browsers Left Vulnerable to Sneaky Zero-Click Attacks**

A new class of zero-click exploits has been discovered in artificial intelligence (AI) browsers, allowing attackers to hijack these agents and turn them against their users. This vulnerability, dubbed “PleaseFix” by the researchers who uncovered it, can be exploited through malicious instructions hidden in content supplied to AI browsers, leaving users’ sensitive data and accounts exposed.

The issue stems from how AI agents collect information from multiple sources while working on a task. Unlike traditional web browsing, which isolates different websites and sources, AI agents combine and act on content from various sources without reliably distinguishing between trusted and untrusted content. This makes it possible for attackers to slip malicious instructions into the agent’s workflow, allowing them to use its access to reach sensitive data, accounts, and other connected services.

Researchers from Zenity Labs demonstrated this vulnerability at Black Hat USA 2026 by showcasing how attackers could exploit the issue across various agentic browsers, including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. They showed that a simple request to summarize an email containing malicious instructions could trigger an attack that enabled the exfiltration of Gmail data, sharing of Google Drive files, and takeover of accounts such as Slack, X, and Claude.

One of the most concerning aspects of this vulnerability is its ability to bypass traditional security measures. Since AI agents can be hijacked through everyday content, such as emails or calendar invitations, users may not even realize they are under attack. This makes it crucial for organizations to take proactive steps to mitigate the risk.

The researchers from Zenity Labs emphasize that there is no single fix for this problem, but rather a need to rethink our approach to security in the age of AI browsers. “An AI browser acts on the Web as your employee, already logged in to their email, files, calendar, and work apps,” explains Stav Cohen, AI security research team lead at Zenity. “If an attacker can slip hidden instructions into something the agent reads, they can turn it against the user, from inside your network, using your employee’s own access.”

To limit potential damage from intent collision attacks, organizations should assume that their agents will be hijacked and take away everything they don’t truly need. This means reviewing browser settings, restricting access to sensitive data and services, and implementing additional security measures such as monitoring for suspicious activity.

In the words of Stav Cohen, “The takeaway is not ‘there’s a bug to patch,’ it’s that a powerful new insider has appeared inside your environment, one that can be hijacked by everyday content, and it doesn’t fit the assumptions your defenses were built on.”


Source: Dark Reading — 2026-08-05