Research · curated 28 Jul 2026
Agentic Browsers Rewind Web Security by 20 years
First reported darkreading.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
PleaseFix shows that every commercial agentic browser can be socially engineered and compromised because they weaken long-standing cross-origin protections, exposing users to account takeover and system-level remote compromise.
Zenity researchers, led by CTO Michael Bargury, disclosed a new class of vulnerabilities dubbed 'PleaseFix' affecting agentic browsers, to be presented at Black Hat. The flaws exploit how agentic browsers strip out cross-origin security mechanisms to let agents reach across web domains, enabling attacks ranging from account takeover to full browser escape and remote compromise of the underlying system.