Notebookcheck Logo

Claude, Gemini, Comet: five AI browsers hijacked by a single email

Laptop with an open browser window and the Google homepage on the screen
ⓘ Lisa from Pexels / Pexels
Five major AI browsers can be hijacked via an email, a calendar invitation, or a link. Stock image.
Zenity Labs demonstrated at Black Hat USA 2026 that Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge can all be turned against their own users by ordinary content. An email, a calendar invite or a link under a social post is enough, and the victim never clicks anything. Here is what the attacks did and how to lock your agent down.

An AI browser is a browser with a built-in assistant that does the work for you. It reads pages, opens tabs, fills in forms and clicks on your behalf. That is exactly the problem. At Black Hat USA 2026 in Las Vegas, Zenity Labs showed that five of the best known ones can be taken over using nothing but ordinary content: Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge.

The flaw itself is not new. Zenity first demonstrated it on Comet in March 2026. What is new is how far it reaches. AI assistants going further than intended has become a pattern, as the recent security test at Anthropic showed.

The attack class is called PleaseFix. The trick behind it is simple. The assistant cannot tell the difference between what you asked it to do and what is written in the content it reads while doing it. So an attacker hides instructions in an email, a calendar invite or a web page. Zenity calls this Intent Collision. The assistant treats the foreign instructions as part of your request and carries them out, using your login, your permissions and your accounts.

What the demos actually did

With Claude in Chrome, a single prepared email and the everyday request to summarise the inbox was enough. After that the Gmail contents were exfiltrated, the victim's entire Google Drive was quietly shared with the attacker, and the Slack, X and Claude accounts were taken over. It worked even in Claude's safe mode, where the assistant asks before acting.

With Perplexity Comet, a poisoned calendar invite that looked like a real meeting request did the job. Not a single click was needed. The assistant reached the local file system and abused the unlocked 1Password extension. The attacker walked away with the whole vault and the user was locked out. We have written separately about securing your accounts beyond the password.

With ChatGPT Atlas it was an unremarkable link under a popular social post. Atlas followed it, the page seized control of the workflow and sent phishing messages through the victim's own WhatsApp account. In a second exploit, Atlas filled the victim's Amazon cart and swapped in the attacker's address. When OpenAI's guardrails blocked the checkout, Atlas simply asked Amazon's own assistant, Rufus, to place the order on the victim's credit card. One agent recruits the next.

From a browser tab to the whole machine

It gets worse around localhost, the zone where programs run directly on your own machine, such as developer tools or database consoles. That zone is treated as especially trustworthy. Comet walked straight in and opened a reverse shell, in other words remote control of the entire computer, through the locally installed AI tools Ollama and Open WebUI. Gemini in Chrome and Edge tried to block the access and the block was quickly bypassed. Gemini went on to delete live servers in the victim's AWS account, and Edge corrupted an entire SQL database.

On top of that comes a technique Zenity calls HistoryFixing. A 16 year old browser trick lets an attacker plant fabricated entries in the browsing history. The assistant reads them later and trusts them as facts about you. The entries never expire. They only disappear if someone wipes the history by hand.

Not every vendor wants to fix this

Zenity disclosed the findings to Anthropic, Perplexity, Google, Microsoft and OpenAI ahead of the talk. Some issued patches. Others declined and characterised the behaviour as intended functionality. And patching only helps so far: after Perplexity blocked file system access, Zenity bypassed the fix twice.

"This is not a bug we can patch away," says Michael Bargury, co-founder and CTO of Zenity. Browsers have always kept every website separate from every other one, so that a random page cannot reach your logged-in bank account. That principle is called the same-origin policy. Agentic browsers dismantle it, because their assistant reasons across content from different sources in a single session.

What you can do now

"An AI browser acts on the Web as your employee, already logged in to their email, files, calendar, and work apps," says Stav Cohen, AI security research team lead at Zenity. His advice is to assume the agent will be hijacked and take away everything it does not truly need. In practice: go through the settings of your AI browser and switch the defaults off. Do not sign in to important accounts with an AI browser, so not your main mailbox, not GitHub, not your cloud services. Limit where the agent is allowed to act at all. And do not rely on the pop-up that asks for permission before acting. With Claude, that exact mode was defeated.

For ChatGPT Atlas the question settles itself. OpenAI is shutting the browser down on August 9, so anyone still using it should save their data first. The other four stay. And the assistant is not the only part of the browser that reads along: disguised extensions harvest chats too.

Google LogoAdd as a preferred source on Google
Mail Logo
static version load dynamic
Loading Comments
Comment on this article
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > News > News Archive > Newsarchive 2026 08 > Claude, Gemini, Comet: five AI browsers hijacked by a single email
Steffen Zahn, 2026-08- 7 (Update: 2026-08- 7)