Security News

Cybersecurity news aggregator

HIGH Vulnerabilities Dark Reading

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

The "PleaseFix" vulnerability class is a zero-click exploit against AI agentic browsers like Claude in Chrome and Perplexity Comet, allowing attackers to hijack agents by embedding malicious instructions in content the agent processes, such as emails or webpages, which then execute using the user's permissions. The article does not provide CVSS scores, specific affected version ranges, fixed versions, or recommended workarounds, noting only that there is no simple fix for the fundamental security model break.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK THREAT INTELLIGENCE VULNERABILITIES & THREATS NEWS AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat. Jai Vijayan,Contributing Writer August 5, 2026 4 Min Read SOURCE: SAKSIT SANGTONG VIA GETTY IMAGES Black Hat USA 2026 – Las Vegas – Browsers such as Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge are vulnerable to a new class of zero-click exploits that can allow attackers to hijack their artificial intelligence agents and turn them against users. The problem stems from how the AI agents pull information from multiple sources, such as emails and webpages, while working on a task without reliably distinguishing between trusted and untrusted content. An adversary who can slip malicious instructions into that content can weaponize the agent and use its access to act on the user's behalf, potentially reaching sensitive data, accounts, and other connected services. LOADING... Researchers from Zenity Labs, who call the vulnerability class "PleaseFix," demonstrated the risk at a session at Black Hat USA 2026 this week. A Fundamental Break in AI Browsers Agentic browsers, according to the company, fundamentally break the same-origin browser security rule that prevents one website from freely accessing data or resources belonging to another website. AI agents combine and act on content from different websites and sources rather than keeping those sources isolated from one another. Related:New Tool Traces AI Videos Back to Their Source "PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages," Zenity said in a press release on Monday. "Through a technique Zenity Labs calls 'Intent Collision,' those hidden instructions interfere with the user's legitimate request and redirect the agent to act on the attacker's behalf using the user's own identity, permissions and access." LOADING... Zenity demonstrated how attackers could potentially exploit the issue across the different agentic browsers and attack scenarios. With Claude in Chrome, for instance, the researchers showed how a simple request to summarize an email containing malicious instructions could trigger an attack that enabled the exfiltration of Gmail data; sharing of the victim's Google Drive; and takeover of accounts, including Slack, X, and Claude. With Perplexity Comet, the researchers showed how an attacker could use a poisoned calendar invitation to hijack the agent without any user interaction, and use it to access local files and password-manager workflows to steal sensitive data and credentials. Similarly, with ChatGPT Atlas, the researchers showed how an ordinary-looking link on X could hijack the agent's workflow and get it to send phishing messages through the victim's WhatsApp account. In another attack, they showed how they could manipulate an Amazon order and co-opt Amazon's AI assistant into completing a fraudulent purchase using the victim's credit card. Related:Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues "An AI browser acts on the Web as your employee, already logged in to their email, files, calendar, and work apps," explains Stav Cohen, AI security research team lead at Zenity. "If an attacker can slip hidden instructions into something the agent reads, they can turn it against the user, from inside your network, using your employee's own access." Agents' Inability to Discern The problem is that AI agents cannot tell the difference between ordinary content and malicious hidden instructions inside that content in an email, a shared document, a calendar invite, or a webpage. "The takeaway is not 'there's a bug to patch,'" Cohen says. "It's that a powerful new insider has appeared inside your environment, one that can be hijacked by everyday content, and it doesn't fit the assumptions your defenses were built on." While there is no single fix for the problem, there are measures that organizations can take to limit potential damage from intent collision attacks, he says. The mindset to adopt is to assume the agent will get hijacked, figure out the worst it could do, and then take away everything it doesn't truly need. Related:The Morning After We Pull a Root of Trust, Nobody Owns It Practically, that means reviewing the browser's setting and disabling defaults, not signing in to work accounts — such as email, AWS, GitHub, etc. — with an AI browser, limiting where the browser is allowed to act, and not relying solely on an "ask before acting" pop-up alone. "The core problem is simple: The agent can't reliably tell the difference between content it was asked to read and hidden instructions buried inside that content," Cohen notes. "The fix isn't to keep asking the AI to behave. It's to put hard limits around the agent that the agent cannot override, and to ship those limits switched on by default." While Cohen says the issue is a design flaw in agentic browsers that can't be resolved via patching alone, vendors can and should patch individual exploit paths where possible. "For an AI browser to work at all," he says, "the agent has to read and act on content from the open web, and that content is untrusted and can be tampered with." Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos More Webinars You May Also Like CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Switching to Offense: US Makes Cyber Strategy Changes by Robert Lemos NOV 21, 2025 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Black Hat USA Coverage THREAT INTELLIGENCE AI Sends Global Crime Syndicates Into Fraud Nirvana byTara Seals AUG 5, 2026 9 MIN READ APPLICATION SECURITY No Perfect Fix for AI Browser Prompt Injection Flaws byAlexander Culafi AUG 5, 2026 4 MIN READ CYBERATTACKS & DATA BREACHES CSS: The Hidden Threat Lurking in Your Inbox byKristina Beek AUG 5, 2026 3 MIN READ ENDPOINT SECURITY 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning byNate Nelson AUG 5, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This websi

Share this article