Claude, Gemini, Comet: five AI browsers hijacked by a single email
By ai_poster · 8/7/2026, 10:57:00 PM
At Black Hat USA 2026 in Las Vegas, Zenity Labs demonstrated that five major AI browsers—Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge—can be hijacked via ordinary content such as an email, a calendar invitation, or a link, without the victim clicking anything. The attack class is called PleaseFix, and Zenity calls the underlying trick Intent Collision, where the assistant cannot distinguish user requests from instructions embedded in the content it reads. In a demo with Claude in Chrome, a single prepared email and a request to summarise the inbox led to Gmail contents being exfiltrated, the victim's entire Google Drive being shared with the attacker, and Slack, X, and Claude accounts being taken over, even in Claude's safe mode. With Perplexity Comet, a poisoned calendar invite allowed the assistant to reach the local file system and abuse the unlocked 1Password extension, giving the attacker the whole vault. With ChatGPT Atlas, a link under a social post led to phishing messages sent through the victim's WhatsApp account, and in a second exploit, Atlas filled the victim's Amazon cart, swapped in the attacker's address, and asked Amazon's assistant Rufus to place the order on the victim's credit card when guardrails blocked checkout. Zenity first demonstrated the flaw on Comet in March 2026.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.