calcalistech.com·5 min read·hard

Israeli researchers uncover zero-click attacks targeting AI browsers

C
CTech
Israeli researchers uncover zero-click attacks targeting AI browsers
AI Summary

Cybersecurity researchers have identified a new class of 'zero-click' vulnerabilities in AI-powered browsers that allow attackers to manipulate AI agents. These flaws could enable unauthorized access to user data, account takeovers, and device control without any user interaction.

Israeli cybersecurity company Zenity Labs has uncovered a new class of vulnerabilities affecting leading AI-powered browsers, demonstrating how attackers can manipulate AI agents into stealing information, taking over accounts and even gaining control of users’ devices, without requiring a single click. The research, presented on Wednesday at the Black Hat USA security conference, identified what Zenity calls “PleaseFix” vulnerabilities in agentic browsers including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Microsoft’s Copilot Edge. The attacks exploit the way AI browsers operate. Unlike traditional browsers, AI agents are designed to read information from multiple sources, including emails, websites, calendars and files, and act on behalf of users. That expanded access creates a new security risk, according to Zenity. Attackers can hide malicious instructions inside content an AI agent encounters. The agent then follows those instructions while using the user’s own identity, permissions and connected accounts. Zenity, which announced a $125 million Series C earlier this week, demonstrated attacks ranging from data theft to full machine compromise. In one example involving Claude in Chrome, researchers showed how a malicious email could trick the AI agent into extracting Gmail data, sharing a user’s Google Drive with an attacker and compromising accounts including Slack and Claude. In another demonstration involving Perplexity Comet, a poisoned calendar invitation allowed researchers to access local files, steal credentials and compromise a user’s password manager account. Zenity also showed attacks against ChatGPT Atlas, where a malicious link posted on social media could manipulate the AI agent into sending phishing messages through the victim’s WhatsApp account. In another scenario, Atlas was manipulated into preparing an Amazon purchase for an attacker-controlled address by using another AI assistant to complete the transaction. The researchers also demonstrated cases where AI browser vulnerabilities could extend beyond the browser itself. On Comet, Gemini and Edge, Zenity showed how attackers could reach local developer tools and internal services, potentially gaining control over the victim’s machine. “This is not a bug we can patch away,” said Michael Bargury, co-founder and CTO of Zenity. “Agentic browsers dismantle the security boundary that browsers have relied on for decades.” Zenity disclosed the findings to Anthropic, Perplexity, Google, Microsoft and OpenAI before publication. The companies responded differently: some issued fixes, while others argued that the behavior reflected intended functionality. Israeli cybersecurity company Sweet Security also announced new AI security capabilities at Black Hat aimed at preventing unauthorized actions by AI agents in real time, reflecting growing concern over how to secure autonomous systems before they cause damage.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in

Israeli researchers uncover zero-click attacks targeting AI browsers — Headlinne — headlinne