forkast.news·4 min read·hard

PleaseFix: Zenity Demonstrates Zero-Click Takeover of Every Major Agentic Browser

H
Heath Callahan
PleaseFix: Zenity Demonstrates Zero-Click Takeover of Every Major Agentic Browser
AI Summary

Security researchers have identified a new vulnerability class called 'Intent Collision' that allows attackers to hijack AI-powered browsers by injecting hidden instructions. This exploit bypasses traditional security boundaries to perform unauthorized actions like data exfiltration.

A new vulnerability class called 'Intent Collision' lets attackers hijack Claude in Chrome, Gemini, Perplexity Comet, ChatGPT Atlas, and Copilot Edge using hidden instructions in any content the agent reads. Some vendors declined to patch.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyai

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in