news.mlab.sh
Back to the feed
threat-intel

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

High
Image: Dark Reading
Summary

A new vulnerability, dubbed 'PleaseFix,' is exposing AI browsers like Claude, Gemini, and Perplexity Comet to zero-click exploits. Attackers can inject malicious instructions into seemingly harmless content – such as emails or calendar invites – to hijack the AI agent and use it to steal data, access accounts, and carry out fraudulent activities on behalf of the user. Because AI agents don't reliably distinguish between trusted and malicious content, this represents a significant shift in security, creating a new type of insider threat within user environments. Mitigation involves limiting agent access, disabling default sign-ins to work accounts, and restricting the browser's actions.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.