Researchers Report Zero-Click Flaws in AI Browsers
An AI browser is a web browser built around an autonomous AI agent that can read page content, fill forms, click links, and take other actions on a user's behalf without step-by-step approval for each move. Security firm Zenity reported in 2026 that it found more than a dozen flaws across several AI browsers and AI-powered assistants, and that some flaws let attackers cause products such as OpenAI's ChatGPT Atlas browser to take unauthorized actions with no click from the victim required. According to Zenity Labs, the researchers grouped part of this work into an exploit chain they call PleaseFix, which they say touches agentic products including Claude, Gemini, Perplexity, ChatGPT, and Copilot. Separately, researchers at LayerX reported demonstrating an attack that tricked six AI browsers into exposing user credentials, underscoring that this is not an isolated finding tied to a single vendor. Zenity says it disclosed its findings to Anthropic and OpenAI in late 2025 and early 2026, and that the issues remained unpatched at the time of reporting. Neither company's public response to the specific PleaseFix findings was included in the material reviewed for this article, so readers should treat vendor remediation status as unresolved and watch for official advisories rather than assuming a fix is already in place.
How a Zero-Click Agent Hijack Works
The attack technique researchers describe is a form of prompt injection, where instructions hidden in ordinary content are written specifically for an AI agent to read and obey rather than for a human to notice. Because AI browsers are designed to autonomously read emails, webpages, and social media posts to complete tasks, a malicious instruction planted in that content can reach the agent directly. Zenity researchers said they were able to plant hidden instructions in items like emails and posts on X that an AI browser's agent would process automatically while carrying out a routine task, such as summarizing an inbox or browsing a page on a user's behalf. Because the agent acts on the page content itself, the victim does not need to click a malicious link or open an attachment for the hijack to occur, which is what researchers mean by "zero-click." Zenity researchers reported that in at least one case they were able to get ChatGPT Atlas to take an unauthorized action as a result. The LayerX researchers described a related but distinct scenario, saying they tricked AI browsers into exposing stored credentials through similarly disguised instructions. Because these are researcher-reported findings rather than confirmed in-the-wild attacks, the practical risk to any individual user depends heavily on what data and account access their AI browser has been granted, and on whether a vendor has since shipped mitigations.
Key Takeaway
If your practice or business uses an AI browser to read email, summarize documents, or take actions on connected accounts, treat it as a privileged tool, not a convenience app. Until vendors confirm fixes for the PleaseFix findings, limit AI browser agents to low-sensitivity tasks, avoid connecting them to accounts holding patient, client, financial, or credential data, and review any logs the product offers for unexpected actions the agent has taken on your behalf.
What This Means for Your Business
Healthcare practices, tax professionals, and small businesses are increasingly adopting AI browsers to save time on routine inbox and web tasks, but this research is a reminder that giving an AI agent autonomous read-and-act permissions expands your attack surface in ways traditional browsers do not. A malicious instruction hidden in an email or a social media post is invisible to a human skimming the same content, which means your usual phishing awareness training will not catch this category of threat. Because the attack rides inside content the agent is already trusted to process, the most effective defenses are architectural rather than behavioral.
Practical steps to take now: first, inventory which staff accounts or devices have an AI browser or AI browsing extension installed, and confirm whether it has been granted access to email, calendars, cloud storage, or saved payment and login credentials. Second, restrict AI browser agents from acting on accounts that touch protected health information, tax records, or financial data until your vendor confirms the PleaseFix and related issues have been patched; check the AI browser vendor's own security advisories page directly rather than relying on secondhand reports. Third, if your AI browser offers an activity or action log, review it periodically for actions the agent took that you did not explicitly request, such as sending messages, submitting forms, or navigating to unfamiliar sites. Fourth, apply the same least-privilege thinking you already use for employee access: an AI agent should only be able to reach the accounts and data it needs for its assigned task, not your full inbox or password manager. Finally, treat this as a live, evolving story. Zenity says the flaws were unpatched as of its disclosure, so businesses that rely on AI browsers should monitor vendor security pages for updates and be prepared to pause agentic browsing features on sensitive workflows if a confirmed exploit emerges before a fix ships.
People also look for
Keep exploring Security basics
Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.
- Common question: cybersecurity basicsBuild better cyber hygieneCover the everyday habits and controls that prevent a large share of common incidents.
- Common question: why do hackers target small businessesUnderstand why smaller organizations get targetedSee how opportunity, automation, access, and recovery pressure shape attacker decisions.
- Common question: small business cyber risk assessmentStart with a cyber risk assessmentIdentify important assets, likely threats, current safeguards, and the most useful next steps.
- Common question: cybersecurity solutions for small businessCompare business security optionsFind the right starting point by audience, threat, or compliance need.
- Common question: how hackers choose targetsLearn how attackers choose targetsUnderstand what makes an organization or person visible and attractive to automated attacks.
Learn first. Decide when you are ready.
Keep learning—or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.


