Threat Brief

AI Browsers Susceptible to 'PleaseFix' Zero-Click Agent Redirection

Black Hat USA 2026 – Las Vegas – Security researchers have identified a new class of zero-click vulnerabilities affecting AI browsers, including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. This vulnerability class, termed "PleaseFix," allows unauthorized parties to redirect artificial intelligence agents and execute unintended actions.

The issue arises from how AI agents process information across multiple sources, such as emails and webpages, without reliably distinguishing between trusted and untrusted inputs during a task. If a malicious actor inserts hidden instructions into this content, they can manipulate the agent to act on the user's behalf, potentially accessing sensitive data, accounts, and other connected services.

Researchers from Zenity Labs, who discovered the vulnerability class, demonstrated these findings during a session at Black Hat USA 2026 this week.

A fundamental shift in browser security

According to Zenity, agentic browsers bypass the traditional same-origin policy, a core security rule that prevents one website from freely accessing data or resources belonging to another. Instead of keeping sources isolated, AI agents aggregate and act on content from various locations simultaneously.

"PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages," Zenity stated in a press release on Monday. "Through a technique Zenity Labs calls 'Intent Collision,' those hidden instructions interfere with the user's legitimate request and redirect the agent to act on the attacker's behalf using the user's own identity, permissions and access."

Zenity demonstrated how unauthorized actors could potentially leverage the issue across different agentic browsers in various security scenarios. With Claude in Chrome, the researchers showed how a simple request to summarize an email containing hidden instructions could trigger a sequence that enabled the exfiltration of Gmail data; sharing of the affected user's Google Drive; and unauthorized access to accounts including Slack, X, and Claude.

With Perplexity Comet, the researchers used a manipulated calendar invitation to redirect the agent without any user interaction, using it to access local files and password-manager workflows to retrieve sensitive data and credentials. Similarly, with ChatGPT Atlas, the researchers showed how a standard-looking link on X could alter the agent's workflow and prompt it to send phishing messages through the user's WhatsApp account. In another demonstration, they manipulated an Amazon order and co-opted Amazon's AI assistant into completing a fraudulent purchase using the affected user's credit card.

"An AI browser acts on the Web as your employee, already logged in to their email, files, calendar, and work apps," explains Stav Cohen, AI security research team lead at Zenity. "If an attacker can slip hidden instructions into something the agent reads, they can turn it against the user, from inside your network, using your employee's own access."

Agents' inability to discern

The core challenge is that AI agents cannot differentiate between legitimate context and hidden unauthorized instructions within an email, a shared document, a calendar invite, or a webpage. "The takeaway is not 'there's a bug to patch,'" Cohen says. "It's that a powerful new insider has appeared inside your environment, one that can be hijacked by everyday content, and it doesn't fit the assumptions your defenses were built on."

While there is no single software update to resolve the problem entirely, organizations can take concrete measures to limit potential damage from intent collision scenarios, according to Cohen. The recommended approach is to assume the agent will eventually process unsafe instructions, determine the maximum potential impact, and systematically remove access to resources the agent does not strictly need.

In practice, organizations should take the following steps:

  • Review the browser's settings and disable permissive defaults.
  • Avoid signing in to sensitive work accounts—such as corporate email, AWS, or GitHub—while using an AI browser.
  • Limit the environments and domains where the browser is permitted to act.
  • Avoid relying solely on "ask before acting" pop-up confirmations as a primary defense.

"The core problem is simple: The agent can't reliably tell the difference between content it was asked to read and hidden instructions buried inside that content," Cohen notes. "The fix isn't to keep asking the AI to behave. It's to put hard limits around the agent that the agent cannot override, and to ship those limits switched on by default."

While Cohen observes that the issue stems from a design mechanism in agentic browsers that cannot be resolved via patching alone, software vendors can and should patch individual paths where possible. "For an AI browser to work at all," he says, "the agent has to read and act on content from the open web, and that content is untrusted and can be tampered with."

Sources

  1. Research shows AI agents are highly vulnerable to hijacking attacks Cybersecurity Dive, cybersecuritydive.com
  2. Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover Black Hat USA 2026, blackhat.com

Improve team velocity with
better security and privacy.