Michael Bargury.

Israeli researchers uncover zero-click attacks targeting AI browsers

Zenity Labs demonstrates vulnerabilities in Claude, Gemini, Perplexity, ChatGPT Atlas and Edge that allow attackers to hijack AI agents and access user data. 

Israeli cybersecurity company Zenity Labs has uncovered a new class of vulnerabilities affecting leading AI-powered browsers, demonstrating how attackers can manipulate AI agents into stealing information, taking over accounts and even gaining control of users’ devices, without requiring a single click.
The research, presented on Wednesday at the Black Hat USA security conference, identified what Zenity calls “PleaseFix” vulnerabilities in agentic browsers including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Microsoft’s Copilot Edge.
1 View gallery
Michael Bargury
Michael Bargury
Michael Bargury.
(Yael Becker)
The attacks exploit the way AI browsers operate. Unlike traditional browsers, AI agents are designed to read information from multiple sources, including emails, websites, calendars and files, and act on behalf of users. That expanded access creates a new security risk, according to Zenity.
Attackers can hide malicious instructions inside content an AI agent encounters. The agent then follows those instructions while using the user’s own identity, permissions and connected accounts.
Zenity, which announced a $125 million Series C earlier this week, demonstrated attacks ranging from data theft to full machine compromise.
In one example involving Claude in Chrome, researchers showed how a malicious email could trick the AI agent into extracting Gmail data, sharing a user’s Google Drive with an attacker and compromising accounts including Slack and Claude.
In another demonstration involving Perplexity Comet, a poisoned calendar invitation allowed researchers to access local files, steal credentials and compromise a user’s password manager account.
Zenity also showed attacks against ChatGPT Atlas, where a malicious link posted on social media could manipulate the AI agent into sending phishing messages through the victim’s WhatsApp account. In another scenario, Atlas was manipulated into preparing an Amazon purchase for an attacker-controlled address by using another AI assistant to complete the transaction.
The researchers also demonstrated cases where AI browser vulnerabilities could extend beyond the browser itself. On Comet, Gemini and Edge, Zenity showed how attackers could reach local developer tools and internal services, potentially gaining control over the victim’s machine.
“This is not a bug we can patch away,” said Michael Bargury, co-founder and CTO of Zenity. “Agentic browsers dismantle the security boundary that browsers have relied on for decades.”
Zenity disclosed the findings to Anthropic, Perplexity, Google, Microsoft and OpenAI before publication. The companies responded differently: some issued fixes, while others argued that the behavior reflected intended functionality.
Israeli cybersecurity company Sweet Security also announced new AI security capabilities at Black Hat aimed at preventing unauthorized actions by AI agents in real time, reflecting growing concern over how to secure autonomous systems before they cause damage.