Groowe Groowe BETA / Newsroom
⏱ News is delayed by 15 minutes. Sign in for real-time access. Sign in

Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers

businesswire.com

Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers LAS VEGAS--( BUSINESS WIRE)--At Black Hat USA 2026, Zenity Labs today released new research demonstrating zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge.

Zenity Labs research exposes the full impact of the PleaseFix vulnerability family, including multiple exploit chains ranging from sensitive data and credential theft to account takeover and remote control of a victim’s machine.

Building on Zenity Labs’ March 2026 disclosure involving Perplexity Comet, the research exposes the full impact of the PleaseFix vulnerability family, including multiple exploit chains ranging from sensitive data and credential theft to account takeover and remote control of a victim’s machine. PleaseFix is a vulnerability that allows attackers to hijack AI agents embedded in agentic browsers and turn them against their own users, without requiring users to click, approve or knowingly execute any malicious action.

Agentic browsers introduce a fundamental change to the browser security model. By allowing their built-in AI agent to reason from different sources within a single session, agentic browsers fundamentally break the same-origin principle. On top of that, agentic browsers operate inside authenticated user sessions with access to email, files, calendars, business applications and other connected services. PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages. Through a technique Zenity Labs calls “Intent Collision,” those hidden instructions interfere with the user’s legitimate request and redirect the agent to act on the attacker’s behalf using the user’s own identity, permissions and access.

“Agentic browsers are trading away decades of hard-won security engineering for convenience,” said Michael Bargury, co-founder and CTO of Zenity. “This is not a bug we can patch away. Browsers rely on SOP to isolate any random website you visit from using your logged in banking account. Agentic browsers dismantle that security boundary. An attacker can trivially get their instructions into your agent’s context. Your agent reads anything on any page, including social media posts or the comment section. Once an attacker can push untrusted content into the agent, they inherit all accounts the user logged into, and in some cases direct access to run code on their local machine. This is an over-agency failure, an inherent implication of the design that makes agentic browsers useful.”

Zenity co-founder and CTO Michael Bargury and Zenity Labs AI Security Researcher Stav Cohen presented the findings at Black Hat USA in “ Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover,” demonstrating how the same underlying trust failure manifests across multiple agentic browser architectures.

Key Research Findings

Responsible Disclosure

Zenity Labs responsibly disclosed its findings to Anthropic, Perplexity, Google, Microsoft and OpenAI ahead of the presentation. Some issued patches, while others declined, characterizing the findings as intended functionality. The mixed response underscores an unresolved gap in how the industry approaches agentic browser security.

Research Availability

The complete research, including technical breakdowns and defender recommendations, is available at labs.zenity.io following the session. Attendees can visit Zenity at booth #5521 for live demonstrations and practical guidance on securing AI agents.

About Zenity

Zenity Labs leads research at Zenity, the first security and governance platform purpose-built for AI agents, with a focus on uncovering and responsibly disclosing vulnerabilities in AI agents and enterprise AI applications. Through adversarial testing and hands-on experimentation across environments, Zenity Labs produces practical insights that help organizations innovate with AI securely. The mission is to illuminate blind spots, advance proven defense techniques, and enable security teams to enforce consistent controls without slowing the pace of AI-driven transformation.