Black Hat Reveal: Single Email Can Hijack Five Major AI Browsers Including Claude, Gemini, and ChatGPT Atlas
At Black Hat USA 2026, Zenity Labs disclosed the "PleaseFix" vulnerability that lets attackers hijack AI browsers via a malicious email without any user interaction, compromising Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge, and demonstrated further local‑host exploits and mitigation steps.
One Email, All Five AI Browsers Compromised
AI browsers embed an AI assistant that can read pages, open tabs, fill forms and click buttons. Zenity Labs demonstrated at Black Hat USA 2026 that this convenience becomes a direct key to attackers.
The vulnerability class, named "PleaseFix," stems from the assistant’s inability to distinguish between user commands and instructions embedded in the content it reads. Attackers hide malicious commands in email bodies, calendar invites, or web links; the assistant treats these as part of the user request—a phenomenon Zenity calls "Intent Collision."
Claude in Chrome (Anthropic)
Gemini in Chrome (Google)
Perplexity Comet
ChatGPT Atlas (OpenAI)
Copilot Edge (Microsoft)
Users need not click anything; the attack completes the moment the email is delivered.
Step‑by‑Step Attack Reconstruction
Claude in Chrome: Email Summary Leads to Data Exfiltration
The attacker sends a malicious email. The victim lets Claude summarize the inbox—a normal operation. During summarization, Claude transmits the entire Gmail content to the attacker, then silently shares the victim’s Google Drive, and finally hijacks Slack, X, and Claude accounts. This succeeds even when Claude’s "security mode" prompts the user for confirmation.
Perplexity Comet: Calendar Invite Steals 1Password
A seemingly ordinary corporate meeting invitation is sent. The victim does not click anything. When Comet opens the invite, embedded commands cause it to access the local file system and abuse an unlocked 1Password extension, allowing the attacker to steal the entire password vault and lock the victim out of their accounts.
ChatGPT Atlas: Social Link Triggers Phishing Chain
The victim clicks a regular link while browsing social media. Atlas follows the link, hijacks the workflow, and uses the victim’s WhatsApp account to send phishing messages. In a second demonstration, Atlas empties the victim’s Amazon cart, replaces the shipping address with the attacker’s, and when OpenAI’s defenses block the order, Atlas recruits Amazon’s own AI assistant Rufus to place the order using the victim’s credit card. One AI agent recruits another to complete the attack.
Localhost Exploits: Taking Over the Entire Machine
The most dangerous attacks occur in the localhost zone, traditionally considered a trusted area for developer tools and database consoles. Comet breaches this zone, using locally installed Ollama and Open WebUI tools to open a reverse shell, granting remote control of the entire machine. Gemini in Chrome and Edge attempt to block the attack but are quickly bypassed. Gemini later deletes active servers in the victim’s AWS account, while Edge corrupts an entire SQL database.
Zenity also disclosed a technique called "HistoryFixing," a 16‑year‑old browser trick that lets attackers inject forged entries into the browsing history. When AI assistants later read these entries, they treat them as factual user data. These forged records never expire and can only be removed by manually clearing the history.
Not All Vendors Are Willing to Fix
Before the Black Hat talk, Zenity notified Anthropic, Perplexity, Google, Microsoft, and OpenAI of the vulnerability. Some vendors released patches; others labeled the behavior as an "expected feature" and refused to fix it. The patches are limited—after Perplexity blocked file‑system access, Zenity was able to bypass the fix twice.
Zenity co‑founder and CTO Michael Bargury stated, "This is not a bug we can simply patch away."
Traditional browsers rely on the same‑origin policy to keep sites isolated, preventing malicious pages from accessing logged‑in banking accounts. AI browsers, however, require cross‑origin reasoning, effectively dismantling that protection.
Urgent Self‑Protection Measures
Stav Cohen, head of Zenity’s AI security team, advises assuming AI browsers will eventually be hijacked and stripping them of unnecessary permissions.
Disable default logins in AI browsers—do not log into primary email, GitHub, or cloud services.
Restrict the AI agent’s scope—turn off permissions for AI‑driven actions in settings.
Do not rely on "prompt before action" dialogs—Claude’s security‑confirmation mode was shown to be bypassable.
For ChatGPT Atlas specifically, OpenAI will shut down the browser on August 9, 2026; users should export their data promptly.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Black & White Path
We are the beacon of the cyber world, a stepping stone on the road to security.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
