News, news analysis, and commentary on the latest trends in cybersecurity technology.

PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.

July 27, 2026

As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser.

Unsurprisingly, this has opened up every commercial agentic browser out in the market to a new arsenal of attack possibilities that ranges from account takeover to full blown browser escape and remote compromise of the underlying system running the browser.