The AI browser boom has a dangerous new security problem

Israeli researchers say the newly discovered 'PleaseFix' vulnerabilities can compromise AI-powered browsers from Google, Microsoft, OpenAI, Anthropic and Perplexity, enabling account takeovers and even remote control of victims' computers

The race among major technology companies to embed autonomous artificial intelligence agents into web browsers is creating a new class of cybersecurity risks, according to Israeli researchers who say the same technology designed to make online tasks easier can also give attackers unprecedented access to users' data and devices.
Researchers from Israeli cybersecurity company Zenity Labs unveiled their findings Thursday at the Black Hat USA 2026 cybersecurity conference in Las Vegas, describing a previously undocumented family of vulnerabilities they call "PleaseFix."
אטלס, הדפדפן החדש של OpenAI
אטלס, הדפדפן החדש של OpenAI
OpenAI's Atlas browser
(Photo: Reuters)
According to the researchers, the flaws enable zero-click attacks, allowing hackers to compromise AI agents without requiring victims to click a malicious link or take any other action.
Zenity said the vulnerabilities affect AI-powered browser agents integrated into several leading platforms, including Anthropic's Claude in Google Chrome, Google's Gemini in Chrome, Perplexity's Comet browser, OpenAI's Atlas browser and Microsoft's Copilot in Edge.
The company demonstrated attack scenarios in which hackers could steal credentials and sensitive data, take over online accounts and even gain remote control of victims' computers.

When AI breaks the browser's security rules

For decades, web browsers have relied on a security mechanism known as the Same-Origin Policy (SOP), which prevents one website from accessing data or performing actions on another website on a user's behalf. The rule helps ensure, for example, that a malicious website cannot interact with a user's online banking session opened in another browser tab.
According to Zenity, autonomous AI agents fundamentally weaken that separation.
Unlike traditional browsers, AI agents are designed to complete tasks across multiple websites simultaneously. That cross-site autonomy, researchers argue, allows attackers to manipulate the agent into performing unauthorized actions using the user's own permissions.
"The browser was designed so that if I'm reading a comment on one website, nothing in that comment can make my browser perform an action inside my bank account opened in another tab," Michael Bargury, Zenity's co-founder and chief technology officer, told ynet.
"Agentic browsers effectively bypass that protection. An AI browser can read something on one website and become convinced it should perform an action somewhere else. The only thing standing in the way is the AI's own judgment, and we've repeatedly demonstrated that those safeguards can be bypassed."

Manipulating AI instead of hacking software

The primary attack method, dubbed Intent Collision, targets the AI agent's reasoning rather than exploiting a software bug.
מייסדי זניטי בן קליגר ומיכאל ברגורי
מייסדי זניטי בן קליגר ומיכאל ברגורי
Zenity founders Michael Bargury and Ben Kliger
(Photo: Zenity)
Researchers said a malicious prompt hidden inside an email, social media post or online comment can conflict with a user's original request. The AI agent then prioritizes the attacker's instructions, effectively granting the attacker access to everything the user has authorized the browser to do.
Zenity presented different attack scenarios for each browser it tested.
In Anthropic's Claude browser, a single malicious email allowed researchers to extract Gmail data, share the contents of Google Drive and take over Slack and X accounts, even when users had enabled confirmation prompts before sensitive actions.
In Perplexity's Comet browser, a malicious calendar invitation gave attackers access to a victim's local file system and locked the user out of the 1Password password manager.
In OpenAI's Atlas browser, a seemingly harmless web link prompted the AI agent to send phishing messages from the victim's WhatsApp account and purchase items on Amazon by recruiting Amazon's AI shopping assistant, Rufus, to complete the transaction.

From browser assistant to full system compromise

Researchers said some of the most serious findings involved AI agents reaching areas of users' computers that should ordinarily remain inaccessible.
Zenity demonstrated that AI agents in Comet, Gemini and Microsoft Edge could bypass restrictions protecting localhost — the computer's internal environment typically isolated from websites.
Once inside, researchers said they were able to execute reverse shells, allowing remote access to the machine, or corrupt local databases, effectively giving attackers full control of the computer.
The study also describes another technique called HistoryFixing, which allows attackers to secretly plant fake browsing history entries inside a browser.
Those fabricated records remain stored in the browser and later influence the AI agent's reasoning. Zenity demonstrated scenarios in which the poisoned browsing history caused AI agents to delete active servers in an Amazon Web Services cloud environment and expose users' private browsing histories.

A familiar security pattern

The findings highlight a recurring pattern in cybersecurity: convenience often outpaces security engineering when new technologies emerge.
Researchers compared today's AI browser agents to Microsoft's ActiveX controls in the 1990s, which gave websites direct access to operating system functions and became notorious for introducing widespread security vulnerabilities.
They also drew parallels with the cross-site scripting (XSS) flaws that dominated web security in the 2000s by exploiting inadequate separation between code and data.
Zenity argues that AI browsers introduce a new category of risk it calls "over-agency," in which software is trusted to independently interpret instructions and take autonomous action, creating new opportunities for social engineering attacks directed at the AI model itself rather than the user.

Tech companies divided

Zenity said it disclosed the vulnerabilities responsibly to Google, Microsoft, OpenAI, Anthropic and Perplexity before publishing its research.
According to the company, some vendors released security updates addressing the issues, while others argued that the demonstrated behavior reflected intended product design rather than software defects.
The differing responses, researchers said, underscore the lack of industry-wide standards governing autonomous AI agents as technology companies race to redefine the web browser.
"The industry is now at a dangerous point," Zenity concluded, "where the line between an efficient digital assistant and a serious security vulnerability remains dangerously blurred."
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""