PleaseFix: Zenity Demonstrates Zero-Click Takeover of Every Major Agentic Browser

Security researchers have identified a new vulnerability class called 'Intent Collision' that allows attackers to hijack AI-powered browsers by injecting hidden instructions. This exploit bypasses traditional security boundaries to perform unauthorized actions like data exfiltration.
Why it matters
As AI agents gain more control over browser environments, this vulnerability exposes a critical flaw in the design of agentic browsers that could lead to widespread account takeovers.
A new vulnerability class called 'Intent Collision' lets attackers hijack Claude in Chrome, Gemini, Perplexity Comet, ChatGPT Atlas, and Copilot Edge using hidden instructions in any content the agent reads. Some vendors declined to patch.
Zenity Labs disclosed a new vulnerability class at Black Hat on August 5 that it calls Intent Collision — a zero-click attack vector that hijacks agentic browsers by injecting hidden instructions into any web page the agent visits. The demonstration compromised Claude in Chrome, Gemini, Perplexity Comet, ChatGPT Atlas, and Copilot Edge without requiring the user to click anything, download anything, or take any action beyond visiting a compromised page.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in