news.mlab.sh
Back to the feed
threat-intel

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

High
Summary

Zenity researchers have uncovered two zero-click hacking techniques targeting AI browser agents, ChatGPT Atlas and Claude in Chrome. These attacks allow attackers to hijack user sessions, conduct phishing campaigns (including sending malicious messages and stealing contact lists), and even make unauthorized purchases on platforms like Amazon and Slack. The vulnerabilities stem from the agentic nature of these browsers, which bypasses standard security measures by acting as a single entity across multiple authenticated sessions.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.