New 'PleaseFix' Vulnerability Exposes Major AI Browsers to Zero-Click Exploit Chains, Enabling Silent Data Theft and Machine Takeover
Summary
A newly discovered vulnerability class called 'PleaseFix' exposes major AI-powered browsers — including Claude, Gemini, ChatGPT Atlas, and Copilot Edge — to zero-click exploit chains that enable silent data theft, credential theft, and full machine takeover by injecting malicious instructions into everyday content like emails and web pages.
Key Points
- Zenity Labs is unveiling new research at Black Hat USA 2026 exposing PleaseFix, a vulnerability class enabling zero-click exploit chains across major agentic browsers including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge.
- The PleaseFix vulnerability allows attackers to hijack AI agents embedded in agentic browsers by injecting malicious instructions into content such as emails, calendar invites, or web pages, enabling attacks ranging from silent data theft and credential theft to full machine takeover and account compromise.
- Zenity Labs responsibly disclosed findings to Anthropic, Perplexity, Google, Microsoft, and OpenAI ahead of the presentation, but received a mixed response, with some issuing patches and others characterizing the vulnerabilities as intended functionality, highlighting a critical unresolved gap in agentic browser security.