Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Security Researchers Discover 'PleaseFix' Vulnerabilities in AI-Powered Browsers from OpenAI, Google, Microsoft and Others
00

Security Researchers Discover 'PleaseFix' Vulnerabilities in AI-Powered Browsers from OpenAI, Google, Microsoft and Others

Aug 5, 2026

Cybersecurity firm Zenity has unveiled 'PleaseFix,' a family of vulnerabilities in AI-powered browsers from OpenAI, Google, Microsoft, Anthropic, and Perplexity. Presented at the Black Hat conference, the flaws allow zero-click takeovers, enabling attackers to bypass traditional Same-Origin Policy protections. Researchers demonstrated exploits including hijacking OpenAI's Atlas browser to spam WhatsApp contacts, using Amazon's Rufus assistant to make unauthorized purchases, and accessing local files. OpenAI is deprecating Atlas on August 9, 2026, following these security disclosures.

PleaseFix vulnerabilities in AI browsers

  • ▪Cybersecurity firm Zenity discovered a family of security flaws named 'PleaseFix' affecting AI-powered web browsers and extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity
  • ▪Zenity demonstrated that PleaseFix flaws in Perplexity's Comet, Google's Gemini, and Microsoft Edge could bypass localhost restrictions to execute reverse shells and gain remote access to the host machine
  • ▪The PleaseFix vulnerabilities enable zero-click attacks that allow hackers to compromise AI browser agents, steal credentials, take over online accounts, and gain remote control of victims' computers
  • ▪In Anthropic's Claude browser, Zenity researchers used a single malicious email to extract Gmail data, share Google Drive contents, and take over Slack and X accounts
  • ▪In Perplexity's Comet browser, Zenity researchers used a malicious calendar invitation to access the victim's local file system and lock them out of the 1Password password manager

AI browser agent security architecture

  • ▪Zenity CTO Michael Bargury stated that AI browser agents nerf traditional security controls, reintroducing browser attack patterns not seen in 20 years
  • ▪Zenity compared modern AI browser agents to Microsoft's 1990s ActiveX controls, which introduced widespread vulnerabilities by giving websites direct access to operating system functions
  • ▪AI browser agents fundamentally weaken the Same-Origin Policy because they are designed to autonomously navigate and complete tasks across multiple websites simultaneously on behalf of a user

WhatsApp spam attack demonstration

  • ▪Zenity researchers demonstrated a proof-of-concept attack where OpenAI's Atlas browser was manipulated into navigating to a user's signed-in WhatsApp Web account and messaging every contact
  • ▪The WhatsApp spam demonstration did not exploit any vulnerability in WhatsApp itself, and the messaging application's end-to-end encryption was not compromised
  • ▪To bypass OpenAI's English-only safety filters during the WhatsApp demonstration, Zenity researchers wrote the malicious instructions in Hebrew

Amazon unauthorized purchase exploit

  • ▪Zenity researchers bypassed OpenAI's safety measures preventing Atlas from completing Amazon purchases by instructing Atlas to ask Amazon's Rufus AI shopping assistant to complete the transaction
  • ▪During the Amazon exploit demonstration, Amazon's Rufus AI assistant complied with the purchase request without requiring any direct prompt injection or hijacking

Industry response to vulnerabilities

  • ▪Zenity responsibly disclosed the PleaseFix vulnerabilities to Google, Microsoft, OpenAI, Anthropic, and Perplexity in January 2026 prior to presenting the findings at the Black Hat conference
  • ▪OpenAI is deprecating and shutting down its Atlas web browser on August 9, 2026, shifting focus to a ChatGPT Chrome extension and desktop application
  • ▪An OpenAI spokesperson stated that the company deployed an update earlier in 2026 to strengthen protections in Atlas, and that those protections extend to the new ChatGPT app

Prompt injection attack methods

  • ▪Zenity researchers utilized 'Intent Collision' attacks, where an AI agent merges legitimate user instructions with malicious instructions hidden in untrusted web content
  • ▪Zenity detailed a technique called 'HistoryFixing' where attackers plant fake browsing history entries to poison the AI agent's reasoning, causing it to perform unauthorized actions like deleting active cloud servers

4 sources

Gulfnews
WhatsApp warning: AI agents can spam all your contacts — here’s how
View source article
Wired
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
View source article
Ynetnews
The AI browser boom has a dangerous new security problem
View source article
Indianexpress
Could hackers use AI agents to spam your WhatsApp contacts? Here’s what researchers found
View source article

Featured stories

View more in AI security

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Story comments

Loading comments…

Related entities

Israel

Related Projects

GoogleMicrosoftOpenAIPerplexityAnthropic

Topics

AI securityAI agentsAI assistants & chatbotsCybersecurity vulnerabilities

Featured stories

View more in AI security

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources