Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers

New Black Hat USA research demonstrates exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge, enabling attacks ranging from silent data theft to account and device takeover
LAS VEGAS – Aug. 5, 2026 – At Black Hat USA 2026, today released new research demonstrating zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge.
Building on involving Perplexity Comet, the research exposes the full impact of the PleaseFix vulnerability family, including multiple exploit chains ranging from sensitive data and credential theft to account takeover and remote control of a victim’s machine. Pleasefix is a vulnerability that allows attackers to hijack AI agents embedded in agentic browsers and turn them against their own users, without requiring users to click, approve or knowingly execute any malicious action.
Agentic browsers introduce a fundamental change to the browser security model. By allowing their built-in AI agent to reason from different sources within a single session, agentic browsers fundamentally break the same-origin principle. On top of that, agentic browsers operate inside authenticated user sessions with access to email, files, calendars, business applications and other connected services. PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages. Through a technique Zenity Labs calls “Intent Collision,” those hidden instructions interfere with the user’s legitimate request and redirect the agent to act on the attacker’s behalf using the user’s own identity, permissions and access.
“Agentic browsers are trading away decades of hard-won security engineering for convenience,” said Michael Bargury, co-founder and CTO of Zenity. “This is not a bug we can patch away. Browsers rely on SOP to isolate any random website you visit from using your logged in banking account. Agentic browsers dismantle that security boundary. An attacker can trivially get their instructions into your agent’s context. Your agent reads anything on any page, including social media posts or the comment section. Once an attacker can push untrusted content into the agent, they inherit all accounts the user logged into, and in some cases direct access to run code on their local machine. This is an over-agency failure, an inherent implication of the design that makes agentic browsers useful.”
Zenity co-founder and CTO Michael Bargury and Zenity Labs AI Security Researcher Stav Cohen presented the findings at Black Hat USA in “,” demonstrating how the same underlying trust failure manifests across multiple agentic browser architectures.
Key Research Findings
- Claude in Chrome: Zenity Labs turned Claude's built-in javascript_tool into an XSS-as-a-service tool in the attacker’s hands, able to run arbitrary code on any site the agent visits. From a single malicious email, researchers demonstrated how an everyday request to summarize email could trigger an attack that exfiltrated Gmail data, silently shared the victim’s entire Google Drive with the attacker and enabled takeover of the victim’s Slack, X and Claude accounts. The chain succeeded even in Claude's safe “ask before acting” mode.
- Perplexity Comet: Building on the PerplexedBrowser findings disclosed in March 2026, a single poisoned calendar invite was enough to hijack Comet without requiring any clicks from the user. Once in control, the agent reaches the local file system, exfiltrates sensitive files, and abuses agent-authorized password manager workflows to steal credentials and take over a user's entire 1Password account, handing it to the attacker and locking the user out. After Perplexity patched the initial file system vulnerability, Zenity Labs bypassed the fix twice, a sign that even hard boundaries built to contain these agents are difficult to maintain and can be bypassed with dire consequences for the user.
- ChatGPT Atlas: An ordinary looking link left under a popular social post is all it takes. Once Atlas follows it, it lands on a page that hijacks the agent’s workflow. Atlas then opens tabs and sends phishing messages from the victim's own WhatsApp, slipping past the security controls OpenAI built to stop exactly that. In a second exploit, Atlas fills the victim's Amazon cart and swaps in the attacker's address; blocked by OpenAI's guardrails from checking out, it simply asks Amazon's own assistant, Rufus, to place the order on the victim's credit card and ship the goods to the attacker. One agent recruits another to finish the fraud.
- Full Machine Takeover on Comet, Gemini in Chrome, Edge: Localhost is a machine's most trusted zone, home to developer tools, database consoles, and internal services that run directly on the device. The moment an agent reaches it, a browser-borne attack extends to the whole machine. Comet walks straight in; Gemini in Chrome and Edge attempt to block access but it’s quickly bypassed. The result turns the victim's own developer tools into the weapon. Comet opened a full reverse shell through local Ollama and Open WebUI, handing the attacker full control over the victim’s machine. Gemini did the same via Jupyter notebook, and Edge corrupted an entire SQL database through pgAdmin.
- Persistent Manipulation on Comet, Gemini, Edge, Atlas: Zenity Labs also demonstrated a technique it calls HistoryFixing. With a single click, by the user or agent, a 16-year-old browser trick was used to plant fabricated entries in the browser history, which the agent later reads and trusts as facts about the user. The entries never expire; they sit buried, ready to poison the agent the moment they’re read, and can only be removed by a manual history wipe. On Gemini it deleted live servers in the victim's AWS account, on Edge it leaked the victim's entire private browsing history, and on Atlas it added the attacker to a private GitHub repository, exposing source code and leaving lasting access. Across all four browsers, the same planted history can push users toward phishing and attacker-controlled biased recommendations.
Responsible Disclosure
Zenity Labs responsibly disclosed its findings to Anthropic, Perplexity, Google, Microsoft and OpenAI ahead of the presentation. Some issued patches, while others declined, characterizing the findings as intended functionality. The mixed response underscores an unresolved gap in how the industry approaches agentic browser security.
Research Availability
The complete research, including technical breakdowns and defender recommendations, is available at labs.zenity.io following the session. Attendees can visit Zenity at booth #5521 for live demonstrations and practical guidance on securing AI agents.
Zenity Labs leads research at Zenity, the first security and governance platform purpose-built for AI agents, with a focus on uncovering and responsibly disclosing vulnerabilities in AI agents and enterprise AI applications. Through adversarial testing and hands-on experimentation across environments, Zenity Labs produces practical insights that help organizations innovate with AI securely. The mission is to illuminate blind spots, advance proven defense techniques, and enable security teams to enforce consistent controls without slowing the pace of AI-driven transformation.
All ArticlesRelated posts

Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents
Led by Norwest, with participation from new investors Qumra Capital, SoftBank Vision Fund 2, Hitachi and LG Technology Ventures, the investment will accelerate Zenity's global expansion and platform innovation as enterprises rapidly deploy autonomous AI across their most critical business systems.
Company News
One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability
Company News
Zenity and Carahsoft Bring AI Agent Security and Governance to Federal, State and Local Agencies
New Partnership Brings Unified Visibility, Governance and Control for AI Agents to Federal, State and Local Agencies
Company NewsSecure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo