Agentic Browsers Rewind Web Security by 20 years
Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote code execution. This stems from the removal of crucial security mechanisms, particularly cross-origin restrictions, that traditionally prevented actions on one website from impacting another. The vulnerabilities are widespread across various agentic browsers, and the researchers highlight that these browsers are essentially ‘black boxes’ with limited transparency, making them risky for enterprise deployments. They recommend using separate credentials and isolated environments to mitigate the risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
