Skip to content
Bellator Cyber Guard
News6 min readStandard

Zero-Click Flaws Found in AI Browsers Like Atlas

Zenity researchers found zero-click flaws in AI browsers including ChatGPT Atlas and Claude, letting attackers hijack agents via emails and web content.

By Bellator Cyber Guard Security Team

Researchers Report Zero-Click Flaws in AI Browsers

An AI browser is a web browser built around an autonomous AI agent that can read page content, fill forms, click links, and take other actions on a user's behalf without step-by-step approval for each move. Security firm Zenity reported in 2026 that it found more than a dozen flaws across several AI browsers and AI-powered assistants, and that some flaws let attackers cause products such as OpenAI's ChatGPT Atlas browser to take unauthorized actions with no click from the victim required. According to Zenity Labs, the researchers grouped part of this work into an exploit chain they call PleaseFix, which they say touches agentic products including Claude, Gemini, Perplexity, ChatGPT, and Copilot. Separately, researchers at LayerX reported demonstrating an attack that tricked six AI browsers into exposing user credentials, underscoring that this is not an isolated finding tied to a single vendor. Zenity says it disclosed its findings to Anthropic and OpenAI in late 2025 and early 2026, and that the issues remained unpatched at the time of reporting. Neither company's public response to the specific PleaseFix findings was included in the material reviewed for this article, so readers should treat vendor remediation status as unresolved and watch for official advisories rather than assuming a fix is already in place.

How a Zero-Click Agent Hijack Works

The attack technique researchers describe is a form of prompt injection, where instructions hidden in ordinary content are written specifically for an AI agent to read and obey rather than for a human to notice. Because AI browsers are designed to autonomously read emails, webpages, and social media posts to complete tasks, a malicious instruction planted in that content can reach the agent directly. Zenity researchers said they were able to plant hidden instructions in items like emails and posts on X that an AI browser's agent would process automatically while carrying out a routine task, such as summarizing an inbox or browsing a page on a user's behalf. Because the agent acts on the page content itself, the victim does not need to click a malicious link or open an attachment for the hijack to occur, which is what researchers mean by "zero-click." Zenity researchers reported that in at least one case they were able to get ChatGPT Atlas to take an unauthorized action as a result. The LayerX researchers described a related but distinct scenario, saying they tricked AI browsers into exposing stored credentials through similarly disguised instructions. Because these are researcher-reported findings rather than confirmed in-the-wild attacks, the practical risk to any individual user depends heavily on what data and account access their AI browser has been granted, and on whether a vendor has since shipped mitigations.

Key Takeaway

If your practice or business uses an AI browser to read email, summarize documents, or take actions on connected accounts, treat it as a privileged tool, not a convenience app. Until vendors confirm fixes for the PleaseFix findings, limit AI browser agents to low-sensitivity tasks, avoid connecting them to accounts holding patient, client, financial, or credential data, and review any logs the product offers for unexpected actions the agent has taken on your behalf.

What This Means for Your Business

Healthcare practices, tax professionals, and small businesses are increasingly adopting AI browsers to save time on routine inbox and web tasks, but this research is a reminder that giving an AI agent autonomous read-and-act permissions expands your attack surface in ways traditional browsers do not. A malicious instruction hidden in an email or a social media post is invisible to a human skimming the same content, which means your usual phishing awareness training will not catch this category of threat. Because the attack rides inside content the agent is already trusted to process, the most effective defenses are architectural rather than behavioral.

Practical steps to take now: first, inventory which staff accounts or devices have an AI browser or AI browsing extension installed, and confirm whether it has been granted access to email, calendars, cloud storage, or saved payment and login credentials. Second, restrict AI browser agents from acting on accounts that touch protected health information, tax records, or financial data until your vendor confirms the PleaseFix and related issues have been patched; check the AI browser vendor's own security advisories page directly rather than relying on secondhand reports. Third, if your AI browser offers an activity or action log, review it periodically for actions the agent took that you did not explicitly request, such as sending messages, submitting forms, or navigating to unfamiliar sites. Fourth, apply the same least-privilege thinking you already use for employee access: an AI agent should only be able to reach the accounts and data it needs for its assigned task, not your full inbox or password manager. Finally, treat this as a live, evolving story. Zenity says the flaws were unpatched as of its disclosure, so businesses that rely on AI browsers should monitor vendor security pages for updates and be prepared to pause agentic browsing features on sensitive workflows if a confirmed exploit emerges before a fix ships.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Security basics

Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.

Learn first. Decide when you are ready.

Keep learning—or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.