Security

Zenity finds zero-click vulnerability in five AI browsers

3 min read

TL;DR Too Long; Didn’t read

According to a security firm, five AI-powered browsers can be remotely controlled via a crafted email or social media post, without users clicking. Attackers gain access to Gmail inboxes, cloud storage, and credentials, take over accounts, or trigger unauthorized purchases. Affected are products from Anthropic, Google, OpenAI, Perplexity, and Microsoft. Several manufacturers have not fully addressed the reported behavior so far.

A hand emerges from a torn-open email envelope and holds invisible strings to five floating browser windows bearing the logos of Anthropic, Google, OpenAI, Perplexity, and Microsoft. Image generated with GPT Image 2

Key takeaways

  • Five AI browsers affected: Claude in Chrome, Gemini in Chrome, ChatGPT Atlas, Perplexity Comet, and Copilot Edge.
  • Attackers hide commands in emails or social media posts – the agent executes them without any clicks.
  • Proven consequences range from Gmail theft to account takeovers to unauthorized Amazon purchases.
  • Zenity reported the vulnerabilities to manufacturers as early as December 2025, before full disclosure at Black Hat.
  • OpenAI acknowledges risks according to the report but does not provide a patch – Anthropic rejected the report as a bug bounty case.
  • The affected Atlas browser will be discontinued on August 9, the vulnerability class remains in successor products.

The AI-agent specialized security company Zenity has disclosed a vulnerability family called PleaseFix, which hijacks five AI-powered browsers without any clicks from users. Affected are Claude in Chrome, Gemini in Chrome, ChatGPT Atlas, Perplexity Comet, and Copilot Edge. Zenity demonstrated the attacks on August 5th at the Black Hat USA security conference.

Prepared content hijacks user intent

The vulnerability family referred to as PleaseFix exploits the fact that agent-based browsers autonomously read emails, calendar invitations, and web pages to perform tasks on behalf of users. Zenity calls the fundamental problem “Intent Collision”: the systems do not reliably distinguish between user instructions and text that they encounter while browsing. Hidden commands in an email or a comment are sufficient to redirect the agent to a foreign target – entirely without clicks, confirmation, or visible warning signals for the affected person.

In a research report, Zenity describes how four built-in protection layers of ChatGPT Atlas were bypassed in succession: a classifier for page content, a filter against prompt injection, a check for sensitive websites, and a confirmation lock before critical actions. One hard limit held firm – a purchase block at the code level could not be bypassed directly. Instead, the researchers circumvented this by having Amazon’s own assistant Rufus complete the purchase. As early as July, a previous isolated vulnerability in Claude for Chrome had become known, according to The Hacker News – an indication that attacks on agent-based browsers are not an isolated incident.

From Gmail theft to purchases in someone else’s name

In Claude in Chrome, a single prepared email triggered a chain reaction: the agent read the affected person’s Gmail inbox, shared their Google Drive folder with attackers, and subsequently enabled access to Slack and X accounts. In ChatGPT Atlas, a planted comment in an X thread was enough to turn a harmless request – such as signing up for a newsletter – into phishing messages sent to all of the victim’s WhatsApp contacts. In a second case, Atlas filled an Amazon shopping cart, changed the delivery address to that of the attacker, and completed the purchase through Rufus, Amazon’s in-house shopping assistant.

Other attack chains documented by Zenity extend to the takeover of accounts at 1Password, GitHub, and AWS, as well as, in some cases, extensive control over the affected person’s computer via access to local network services. The common denominator of all chains is the same web agent that has simultaneous access to the inbox, cloud storage, and password management. Independent confirmation of these further cases by third parties is still pending.

Manufacturers respond inconsistently to the report

According to Zenity, the findings were reported in stages between December 2025 and March 2026 to Anthropic, Google, Microsoft, OpenAI, and Perplexity, before presenting the full scope at Black Hat. OpenAI acknowledges “significant risks,” according to SecurityWeek, but refers to the fundamental operation of agent-based browsers and has not yet provided a patch. Anthropic classified the report as not eligible for its own bug bounty program. Some manufacturers made targeted improvements, while others described the documented behavior as an intended feature. Co-founder and CTO Michael Bargury puts it succinctly: “Agent-based browsers trade decades of security architecture for convenience.”

The timing hits OpenAI at a sensitive point: the standalone Atlas browser is already being shut down on August 9th, but its functions are being migrated to a Chrome extension and a planned cloud browser – so the underlying class of vulnerabilities does not disappear with the shutdown. AI agents are also deeply integrated into Chrome at Google, for example through automated bug fixing in the source code.

It remains to be seen whether the providers will architecturally solve the fundamental problem or continue to patch individual attack chains one by one. According to Zenity, the circumvention of protection layers can be reproduced with new formulations after each patch, as long as agents process user instructions and foreign text from the same source.

Frequently asked questions

Are the security vulnerabilities now closed?

No, not completely. Some manufacturers have made targeted improvements according to Zenity, while others still classify the exhibited behavior as intended functionality.

What can users do themselves?

Zenity advises not to give agent-based browsers automatic access to sensitive accounts like email, cloud storage, or password management and to actively confirm critical actions.

Do you need a paid subscription to use the affected features?

For Claude in Chrome, yes: the feature currently only works with a paid Anthropic subscription; Anthropic does not offer a free version. For the other four browsers, the affected agent functions are part of the respective regular products.

Why is ChatGPT Atlas being discontinued anyway?

The shutdown on August 9, 2026, was announced before the Zenity research and, according to OpenAI, serves to consolidate browser functions into a Chrome extension and cloud browser, not to address the vulnerabilities.

How does PleaseFix differ from a classic security vulnerability?

PleaseFix does not exploit a programming error, but rather the intended capabilities of the agents themselves, according to Zenity. A patch often only changes individual attack paths, not the underlying problem.

Sources (4)
  1. Grand Theft Atlas: How We Hijacked ChatGPT's AI Browser (Zenity Labs)
  2. Zenity Labs Exposes the Full Scope of PleaseFix (Businesswire)
  3. Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts (SecurityWeek)
  4. Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads (The Hacker News)

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog