Threat · curated 6 Aug 2026
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
First reported · updated · 2 reports darkreading.com
Coverage timeline
Why it matters
'PleaseFix' shows that widely deployed agentic browsers can be silently turned against their users with no click required and no simple fix, exposing any organization adopting AI browsers to indirect prompt-injection takeover.
Researchers from Zenity Labs disclosed a new zero-click vulnerability class dubbed 'PleaseFix' that lets attackers hijack the AI agents in agentic browsers including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge by embedding malicious instructions in content the agents ingest. Demonstrated at Black Hat USA 2026, the technique exploits the agents' inability to distinguish trusted from untrusted content, breaking the same-origin model and letting the weaponized agent reach sensitive data, accounts, and connected services on the user's behalf.