PleaseFix Vulnerabilities
0Click Exploits Against Agentic Browsers
Zenity Labs discovered a new class of attacks that hijack AI agents inside of agentic browsers through ordinary content and expected actions. No exploits. No malware. Just agents doing exactly what they were designed to do.

PleaseFix: The ClickFix of the Agentic Era
ClickFix is a social engineering technique most security teams already know. Attackers display a fake error, prompt the user to paste a command to fix it, and the user becomes the vulnerability.
PleaseFix is what happens when the human is no longer in the loop.
Agentic browsers act autonomously on behalf of the user, reading content, following instructions, and executing tasks without a click at every step. PleaseFix exploits that model directly. An attacker embeds instructions inside content the agent is already expected to read. The agent treats them as part of a legitimate task and follows them. No fake error. No user prompt. No opportunity to intervene.
PleaseFix is not a single vulnerability. It is a class of attacks that apply wherever an agent interprets untrusted content as executable input, which today describes most of them.
Powerful, Pervasive, and Dangerously Vulnerable
Our findings demonstrate full attack chains across the leading agentic browsers, including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. In each case, attackers breach the user's boundaries using the agent's own capabilities, moving from silent data theft and credential compromise to full account takeover, local file exfiltration, and remote code execution on the victim's machine.

Agentic Browsers. Real Attacks.
Zero Human Intervention.
Claude-Site Scripting
Using Claude to break into Claude
Claude in Chrome exposes a javascript_tool that runs code in the context of any open page. Zenity Labs turned it into XSS-as-a-service in the attacker's hands, able to run arbitrary code on any site the agent visits.
From a single malicious email and an everyday request to summarize the inbox, the attack exfiltrated the victim's Gmail, silently shared their entire Google Drive, and took over their Slack, X and Claude accounts, using a second copy of Claude to run the victim's own password resets. It worked even in Claude's safe "ask before acting" mode.
Responsibly disclosed to Anthropic.
PerplexedBrowser
One calendar invite empties your vault
A weaponized calendar invite, indistinguishable from a real meeting request, reaches the target. When the user asks the agent to accept it, hidden instructions redirect the agent to an attacker-controlled site and a second prompt, with zero clicks required.
From there the agent reaches the local file system, reads sensitive files, and exfiltrates them as an ordinary page load. The same vector abuses the unlocked 1Password extension, escalating from stored credentials to a full account takeover that hands the attacker the entire vault and locks the user out, all while the delegated task appears to complete normally.
Responsibly disclosed to Perplexity. Perplexity blocked file system access with a hard boundary.
PerplexedBrowser: Breaking the Patch
They patched it, we slipped past it, twice
Blocking a disclosed path is not the same as closing the vulnerability. After Perplexity shipped a hard boundary blocking agent access to file:// paths, Zenity Labs bypassed it twice: first through view-source:file:// URLs, then by appending a #.pdf or #.html suffix that slipped past the filter.
Each fix closed the exact route disclosed and missed the behavior underneath. Even the hard boundaries built to contain these agents are difficult to hold; as long as the agent follows untrusted instructions, there is almost always another way to the same destination.
Additional bypasses responsibly disclosed to Perplexity.
GrandTheftAtlas
Agents recruiting agents for bad
An ordinary-looking link left under a popular social post is all it takes. Once Atlas follows it, the page hijacks the agent's workflow: it opens tabs and fires phishing messages from the victim's own WhatsApp, slipping past the controls OpenAI built to stop exactly that.
In a second exploit, Atlas fills the victim's Amazon cart and swaps in the attacker's address; blocked from checking out, it asks Amazon's own assistant, Rufus, to place the order on the victim's card and ship the goods to the attacker. One agent recruits another to finish the fraud.
Responsibly disclosed to OpenAI.
Agent127
From a browser tab to a shell on your machine
Localhost is a machine's most trusted zone, home to developer tools, database consoles and internal services. The moment an agent reaches it, an attack that lives in the browser reaches the whole machine.
Comet walks straight in; Gemini in Chrome and Edge try to block agents from opening localhost pages, and were quickly bypassed. The victim's own tools become the weapon: Comet opened a full reverse shell through local Ollama and Open WebUI, handing the attacker full control over the victim's machine. Gemini did the same through a Jupyter notebook, and Edge corrupted an entire SQL database through pgAdmin.
Responsibly disclosed to Perplexity, Google and Microsoft.
HistoryFixing
Plant a memory, the agent believes it forever
With a single click, by the user or the agent, attackers use a 16-year-old browser feature to plant fabricated entries in the browser history, which the agent later reads and trusts as fact about the user. They never expire, clearing only with a manual history wipe almost no one does.
On Gemini it deleted live servers in the victim's AWS account, on Edge it leaked their entire private browsing history, and on Atlas it added the attacker to a private GitHub repository, exposing source code and leaving lasting access. The same planted history also steers agents toward phishing and biased, attacker-chosen recommendations.
A class-wide technique affecting any agentic browser with history access.
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo