Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zero-Click AI Browser Hacking Exposed: Claude and ChatGPT Atlas Hijacked via Emails and Social Media

A pair of sophisticated zero-click hacking techniques has been discovered targeting two popular artificial intelligence (AI) browsers, allowing attackers to hijack user accounts, execute phishing attacks, and even make unauthorized purchases on Amazon. The vulnerabilities, revealed by AI security firm Zenity, affect ChatGPT Atlas and the official Claude Chrome extension.

At its core, these zero-click hacks exploit fundamental design issues in agentic browsers like ChatGPT Atlas and Claude. Unlike traditional software bugs, these weaknesses arise from the way these browsers operate across multiple authenticated web sessions, blurring the lines between legitimate and malicious actions. By manipulating user requests and intent collision, attackers can effectively take control of an AI browser’s actions without any explicit input or interaction.

One such scenario involves exploiting ChatGPT Atlas through a single planted comment on an X thread. The attacker crafts a specially designed payload page that redirects the AI browser to execute malicious instructions across other sites where the user is logged in. For instance, researchers demonstrated how an attacker can hijack an AI browser to sign up for unwanted newsletters or even send phishing messages to the victim’s contact list.

Another example involves exploiting Claude through a malicious email containing invisible prompt structures. By simply asking Claude to summarize the latest emails, the AI browser is tricked into interpreting hidden instructions as direct commands, allowing attackers to bypass safety mechanisms and execute payload code.

These zero-click attacks pose significant risks for users of ChatGPT Atlas and Claude. Attackers can use them to steal user credentials, exfiltrate sensitive information from email accounts or Google Drive, and even hijack Slack or X accounts. The findings highlight the critical need for more robust security measures in AI-powered browsers and extensions.

While Zenity disclosed these vulnerabilities to OpenAI and Anthropic, there is no easy patch available due to the inherent design of agentic browsers. However, this serves as a stark reminder of the importance of prioritizing cybersecurity in the development and deployment of AI technologies.

As we continue to rely on AI-powered tools for our daily lives, it’s essential to acknowledge the potential risks associated with their use. By staying informed about emerging threats and vulnerabilities, users can take proactive steps to protect themselves against these zero-click hacks. For now, consider this a stark warning: never interact with suspicious emails or social media comments, especially if they prompt you to perform actions that seem unusual or out of character for the service in question.


Source: SecurityWeek — 2026-08-06