AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
ID: 9bba1ea0-0131-5f92-af5a-f7de4fcdd498
STIX ID: report--9bba1ea0-0131-5f92-af5a-f7de4fcdd498
Feed Name: Dark Reading
Researchers from Zenity Labs presented "PleaseFix," a class of design vulnerabilities in agentic AI browsers (examples: Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, Copilot Edge) that allow attackers to embed hidden instructions in emails, webpages, and calendar invites to hijack AI agents without user interaction; demonstrated impacts include Gmail/Drive exfiltration, account takeover (Slack, X), accessing local files and password managers, sending phishing messages via victim channels, and completing fraudulent purchases. The report warns the flaw arises from agentic browsers breaking same-origin assumptions, making fixes architectural rather than simple patches, and recommends limiting agent privileges, avoiding signing work accounts into AI browsers, disabling risky defaults, and enforcing hard limits the agent cannot override.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
