Cybersecurity firm Zenity has unveiled 'PleaseFix,' a family of vulnerabilities in AI-powered browsers from OpenAI, Google, Microsoft, Anthropic, and Perplexity. Presented at the Black Hat conference, the flaws allow zero-click takeovers, enabling attackers to bypass traditional Same-Origin Policy protections. Researchers demonstrated exploits including hijacking OpenAI's Atlas browser to spam WhatsApp contacts, using Amazon's Rufus assistant to make unauthorized purchases, and accessing local files. OpenAI is deprecating Atlas on August 9, 2026, following these security disclosures.
Aug 9, 2026 · 9 sources
Aug 7, 2026 · 6 sources
Aug 6, 2026 · 4 sources
Aug 10, 2026 · 1 source
Story comments
Loading comments…