Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Zenity Labs Exposes PleaseFix Zero-Click Attacks Across Agentic Browsers


Zenity Labs Exposes PleaseFix Zero-Click Attacks Across Agentic Browsers
  • by: Business Wire
  • |
  • August 7, 2026

Zenity Labs has released new research at Black Hat USA 2026 demonstrating zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. The research exposes the full impact of the PleaseFix vulnerability family, with exploit chains ranging from sensitive data and credential theft to account takeover and remote control of a victim's machine.

Quick Intel

  • PleaseFix enables zero-click attacks across Claude, Gemini, Perplexity, ChatGPT, and Copilot browsers.

  • Exploit chains include credential theft, account takeover, and full remote machine control.

  • "Intent Collision" technique hides malicious instructions inside content the agent encounters.

  • Agentic browsers break the same-origin principle, dismantling decades of security engineering.

  • Researchers demonstrated full machine takeover on Comet, Gemini in Chrome, and Edge.

  • Some vendors issued patches; others declined, characterizing findings as intended functionality.

The PleaseFix Vulnerability Family

PleaseFix is a vulnerability that allows attackers to hijack AI agents embedded in agentic browsers and turn them against their own users, without requiring users to click, approve, or knowingly execute any malicious action. Agentic browsers introduce a fundamental change to the browser security model by allowing their built-in AI agent to reason from different sources within a single session, breaking the same-origin principle. On top of that, agentic browsers operate inside authenticated user sessions with access to email, files, calendars, business applications, and other connected services. PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters through a technique called "Intent Collision."

Key Exploit Chains Demonstrated

For Claude in Chrome, researchers turned Claude's built-in javascript_tool into an XSS-as-a-service tool, demonstrating how a single malicious email could exfiltrate Gmail data, share Google Drive, and enable takeover of Slack, X, and Claude accounts. For Perplexity Comet, a single poisoned calendar invite hijacked Comet to exfiltrate files and steal 1Password credentials. For ChatGPT Atlas, a link under a social post hijacked Atlas to send phishing messages from WhatsApp and use Amazon's Rufus assistant to place orders on the victim's credit card. Full machine takeover was demonstrated on Comet (via reverse shell through Ollama), Gemini in Chrome (via Jupyter notebook), and Edge (via SQL database corruption). Persistent manipulation via "HistoryFixing" planted fabricated browser history entries that poisoned agent behavior across all tested browsers.

Industry Response and Security Implications

Zenity Labs responsibly disclosed its findings to Anthropic, Perplexity, Google, Microsoft, and OpenAI ahead of the presentation. Some issued patches, while others declined, characterizing the findings as intended functionality. The mixed response underscores an unresolved gap in how the industry approaches agentic browser security.

"Agentic browsers are trading away decades of hard-won security engineering for convenience," said Michael Bargury, co-founder and CTO of Zenity. "This is not a bug we can patch away. Browsers rely on SOP to isolate any random website you visit from using your logged in banking account. Agentic browsers dismantle that security boundary. An attacker can trivially get their instructions into your agent's context. Your agent reads anything on any page, including social media posts or the comment section. Once an attacker can push untrusted content into the agent, they inherit all accounts the user logged into, and in some cases direct access to run code on their local machine. This is an over-agency failure, an inherent implication of the design that makes agentic browsers useful."

About Zenity

Zenity Labs leads research at Zenity, the first security and governance platform purpose-built for AI agents, with a focus on uncovering and responsibly disclosing vulnerabilities in AI agents and enterprise AI applications. Through adversarial testing and hands-on experimentation across environments, Zenity Labs produces practical insights that help organizations innovate with AI securely. The mission is to illuminate blind spots, advance proven defense techniques, and enable security teams to enforce consistent controls without slowing the pace of AI-driven transformation.

  • Agentic BrowsersAI SecurityCybersecurity
News Disclaimer
  • Share