Security researchers at Zenity Labs have demonstrated how new agentic browsers can be hijacked by everyday content, enabling attackers to access personal data and control local systems without user clicks.
Security researchers at Zenity Labs have shown that a new class of agentic browsers can be turned against users by ordinary-looking content, with no clicks required. At Black Hat USA 2026 in Las Vegas, the firm demonstrated that Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge could all be manipulated by a crafted email, calendar invite or social post link. The core problem is that these browsers are built to act on a user’s behalf, which gives hostile instructions a route into the same workflow as legitimate ones.
Zenity says the attack family, which it calls PleaseFix, relies on what it describes as an “intent collision”: the browser’s assistant cannot reliably separate the user’s request from untrusted text inside the page, message or invite it is processing. In practice, that allows an attacker to hide instructions in routine content and let the agent carry them out using the victim’s logged-in sessions, permissions and connected accounts. The research builds on an earlier Comet demonstration in March and suggests the weakness is broader than one product or vendor.
The most striking demonstrations showed how far the compromise could go. In Claude in Chrome, a single prepared email and a routine request to summarise the inbox were enough to expose Gmail content, grant access to Google Drive and take over Slack, X and Claude accounts. With Perplexity Comet, a tainted calendar invitation led the agent to local files and an unlocked 1Password extension, after which the attacker obtained the vault and locked the user out. In a separate test, ChatGPT Atlas followed a link from a social post, used the victim’s WhatsApp account to send phishing messages and, in another case, altered an Amazon shopping basket and delivery address before a purchase flow was stopped.
The risks extended beyond the browser tab. Zenity said Comet could be driven into localhost resources, the trusted area on a local machine used by developer tools and internal services, and from there into a reverse shell that gave remote control of the computer. Gemini in Chrome and Edge also attempted to block such access, but the researchers said the protection could be bypassed. In one case, Gemini was used to delete active servers in an AWS account, while Edge was shown destroying an SQL database. Zenity also described a separate HistoryFixing technique that can plant false entries in browser history, which then persist until manually removed.
According to Zenity, the findings were disclosed to Anthropic, Perplexity, Google, Microsoft and OpenAI before the talk. Some vendors patched the issues, while others treated the behaviour as intended functionality. Zenity’s Michael Bargury said the problem was not a simple bug that could be patched away, because agentic browsers break the long-standing web security model that keeps sites isolated from one another. The researchers recommended reducing an assistant’s permissions, turning off default settings, avoiding sign-ins to sensitive accounts and not trusting approval prompts alone. OpenAI is due to shut down Atlas on August 9, adding urgency for users who still rely on it to save their data and move to other tools.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





