• News/
  • darkreading-20260805233000

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Dark Reading
·
Jai Vijayan
·
Published Aug 5, 2026
·
Updated

Black Hat USA 2026 – Las Vegas – Browsers such as Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge are vulnerable to a new class of zero-click exploits that can allow attackers to hijack their artificial intelligence agents and turn them against users. The problem stems from how the AI agents pull information from multiple sources, such as emails and webpages, while working on a task without reliably distinguishing between trusted and untrusted content. An adversary who can slip malicious instructions into that content can weaponize the agent and use its access to act on the user's behalf, potentially reaching sensitive data, accounts, and other connected services. Researchers from Zenity Labs, who call the vulnerability class "PleaseFix," demonstrated the risk at a session at Black Hat USA 2026 this week. Agentic browsers, according to the company, fundamentally break the same-origin browser security rule that prevents one website from freely accessing data or resources belonging to another website. AI agents combine and act on content from different websites and sources rather than keeping those sources isolated from one another. "PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages," Zenity said in a press release on Monday. "Through a technique Zenity Labs calls 'Intent Collision,' those hidden instructions interfere with the user's ...

Read full article

Affected Software

5 affected components
Anthropic Claude in Chrome
Google Gemini in Chrome
Perplexity Comet
OpenAI ChatGPT Atlas
Microsoft Copilot Edge
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in AI browsers that are susceptible to zero-click agent hijacking.

2

What security implications are discussed?

The article highlights the potential for attackers to hijack artificial intelligence agents within browsers to compromise user security.

3

What products or software are affected?

The affected browsers include Anthropic Claude in Chrome, Google Gemini in Chrome, Perplexity Comet, OpenAI ChatGPT Atlas, and Microsoft Copilot Edge.

4

What is a zero-click exploit?

A zero-click exploit is a type of attack that does not require any user interaction to be executed.

5

When was this vulnerability disclosed?

The vulnerability was disclosed on August 5, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203