Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers

New Black Hat USA research demonstrates exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge, enabling attacks ranging from silent data theft to account and device takeover

At Black Hat USA 2026, Zenity Labs today released new research demonstrating zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge.

Building on Zenity Labs’ March 2026 disclosure involving Perplexity Comet, the research exposes the full impact of the PleaseFix vulnerability family, including multiple exploit chains ranging from sensitive data and credential theft to account takeover and remote control of a victim’s machine. PleaseFix is a vulnerability that allows attackers to hijack AI agents embedded in agentic browsers and turn them against their own users, without requiring users to click, approve or knowingly execute any malicious action.

Agentic browsers introduce a fundamental change to the browser security model. By allowing their built-in AI agent to reason from different sources within a single session, agentic browsers fundamentally break the same-origin principle. On top of that, agentic browsers operate inside authenticated user sessions with access to email, files, calendars, business applications and other connected services. PleaseFix exploits this trust model by placing malicious instructions inside content the agent encounters, such as emails, calendar invitations or web pages. Through a technique Zenity Labs calls “Intent Collision,” those hidden instructions interfere with the user’s legitimate request and redirect the agent to act on the attacker’s behalf using the user’s own identity, permissions and access.