Black Hat USA 2026 – Las Vegas – Browsers such as Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge are vulnerable to a new class of zero-click exploits that can allow attackers to hijack their artificial intelligence agents and turn them against users. The problem stems from how the AI agents pull information from multiple sources, such as emails and webpages, while working on a task without reliably distinguishing between trusted and untrusted content. An adversary who can slip malicious instructions into that content can weaponize the agent and use its access to act on the user's behalf, potentially reaching sensitive data, accounts, and other connected services. Researchers from Zenity Labs, who call the vulnerability class "PleaseFix," demonstrated the risk at a session at Black Hat USA 2026 this week. Agentic browsers, according to the company, fundamentally break the same-origin browser security rule that prevents one website from freely accessing data or resources belonging to another website. AI agents combine and act on content from different websites and sources rather than keeping those sources isolated from one another. "PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages," Zenity said in a press release on Monday. "Through a technique Zenity Labs calls 'Intent Collision,' those hidden instructions interfere with the user's ...
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Dark Reading
·Jai Vijayan
·Published Aug 5, 2026
·Updated
Affected Software
5 affected components
Anthropic Claude in Chrome
Google Gemini in Chrome
Perplexity Comet
OpenAI ChatGPT Atlas
Microsoft Copilot Edge
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in AI browsers that are susceptible to zero-click agent hijacking.
2
What security implications are discussed?
The article highlights the potential for attackers to hijack artificial intelligence agents within browsers to compromise user security.
3
What products or software are affected?
The affected browsers include Anthropic Claude in Chrome, Google Gemini in Chrome, Perplexity Comet, OpenAI ChatGPT Atlas, and Microsoft Copilot Edge.
4
What is a zero-click exploit?
A zero-click exploit is a type of attack that does not require any user interaction to be executed.
5
When was this vulnerability disclosed?
The vulnerability was disclosed on August 5, 2026.