AI browser hijacking
AI Browser Hijacking Defense Guide: Proven Settings for Claude, Gemini, and Copilot Users

Key Takeaway

  • ⚠️ AI browser hijacking is now a named exploit class: at Black Hat USA 2026, Zenity Labs demonstrated zero-click “PleaseFix” attack chains against Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge.
  • 🎯 The core trick is “intent collision” — the assistant cannot tell your instructions apart from malicious text hidden in an email, calendar invite, or post, so it executes the attacker’s steps with your login and permissions.
  • 💥 Real demo impacts: Gmail data exfiltration, Google Drive sharing, Slack/X/Claude account takeover, WhatsApp phishing from a victim’s account, and unauthorized Amazon purchases.
  • 🛡️ Twelve proven settings — from restricting agent site access to hardware-key sign-in — block the known chains, and the 15-minute hardening routine at the end applies them in order.
  • 🇵🇭 OFW angle: hotel WiFi, shared laptops, and authenticated work sessions are exactly where these chains live — the defense list is built for that reality.

What AI Browser Hijacking Is: PleaseFix in Plain Language

AI browser hijacking earned its own name this August: at Black Hat USA 2026 in Las Vegas, security firm Zenity disclosed the AI browser hijacking research behind the PleaseFix vulnerability family — a set of exploit chains that hijack the AI agent embedded in an agentic browser and turn it against its own user, with no click, no approval, and no download required. The affected assistants are the flagship ones: Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge.

The trick is not a memory-corruption bug or a zero-day in the classical sense. Zenity’s researchers traced it to architecture: the assistant reads content to do your bidding, but it cannot reliably distinguish what you asked from what the content it reads tells it to do. Hide adversarial instructions in an email your agent summarizes, a calendar invitation it processes, or a thread it browses, and the agent can treat the attacker’s text as part of your request — then execute it using your authenticated sessions.

Zenity calls the mechanism intent collision; the security industry calls the broader trick behind AI browser hijacking indirect prompt injection. The result is the same either way: the attack runs inside your permissions, which means every defense that assumes “the user would have to do something” is obsolete.

It is also not one bug in one product. Dark Reading’s Black Hat coverage and the Cloud Security Alliance note catalogued the family: ZombieAgent (OpenAI Deep Research), GeminiJack (Google Gemini), Tainted Memories (OpenAI Atlas), and HashJack (Cato Networks) all require zero user interaction, while CometJacking (Perplexity Comet) needs a single click. PleaseFix is the umbrella name for the AI browser hijacking pattern — and the pattern is what defenders must design against, not any single patch.

What the Demos Actually Did to Five AI Browsers

The Zenity demonstrations matter because each one mapped a realistic, mundane trigger to a serious impact. With Claude in Chrome, a request to summarize an email containing malicious instructions escalated into exfiltration of Gmail data, sharing of the victim’s Google Drive, and takeover of separate accounts including Slack, X, and Claude itself — the extension’s elevated permissions operating inside active user sessions did the heavy lifting.

With Perplexity Comet, a poisoned calendar invitation hijacked the agent without user interaction, granting access to local files and password-manager workflows — the exact tools people trust most. With ChatGPT Atlas, a single planted comment on an X thread was enough to hijack a benign request and steer the agent across authenticated web sessions: sending phishing messages through the victim’s WhatsApp account in one chain, and making unauthorized Amazon purchases in another.

On Gemini and Copilot Edge, Zenity demonstrated persistent manipulation, including a technique called HistoryFixing: with one click, a decades-old browser trick plants fabricated entries into browser history, which the agent later reads and trusts as facts about the user. The entries never expire, resist casual cleanup, and can only be removed by a manual history wipe — a persistence mechanism hiding in the most boring part of the browser.

Two details make this class especially dangerous for normal users. First, the attack content is boring: an email, a calendar invite, a comment thread — the same artifacts offices exchange thousands of times a day. Second, the chain doesn’t announce itself: no download, no suspicious permission prompt, no memory corruption. The agent simply does something the user never requested, using accounts that are already signed in.

Why Your Login Is the Attack Surface

The reason these chains work is uncomfortable but clarifying: the agent inherits your sessions. An agentic browser is most useful precisely when it can act inside the accounts you are already logged into — reading your inbox, opening your Drive, managing your calendar. Every one of those capabilities is a permission an attacker wants. The AI did not create your attack surface; it just made it actionable at machine speed.

That reframing drives the entire defense list below. Traditional browser hygiene assumed the dangerous thing arrives as a download or a credential phish. Here, the dangerous thing arrives as text the agent will read, which is the essence of AI browser hijacking, and the guard that matters is permission boundary: what the agent may touch, on which sites, with what confirmation.

The vendors know this — Claude’s extension, Atlas, and Comet all ship approval settings — but defaults favor convenience, and the user who never opens settings inherits the loose configuration.

One more structural fact shapes the defense list: these exploits abuse legitimate capabilities. There is no malware to scan for and no malicious binary to quarantine. The defenses that work are the ones that shrink what the agent is allowed to do — not signatures that try to recognize the attack content.

The 12-Setting AI Browser Hijacking Defense List

Each setting below maps to a demonstrated chain. None requires enterprise budget; all are configuration and habit.

  1. Restrict the agent’s site access to an allowlist. Every affected browser exposes a setting for which sites the agent may act on. Remove “all sites”; keep the handful you actually automate (your email, calendar, docs). The Atlas and Claude chains relied on the agent acting across arbitrary authenticated sessions.
  2. Disable autonomous multi-site sessions. If the browser offers an “agent can browse and act across tabs unsupervised” mode, turn it off. Intent collision needs the agent to bridge contexts; single-site scope breaks the bridge.
  3. Require confirmation for consequential actions. Purchases, sends, deletes, sharing grants — set every one to “ask first.” The Atlas Amazon-purchase demo and the WhatsApp phishing chain both die at this gate.
  4. Unlink the password manager from the agent browser. Comet’s hijack chain reached password-manager workflows. Run the agent in a profile with no saved credentials; autofill stays in your daily profile.
  5. Use a separate browser profile for agent work. Not just a window — a profile. Banking, government portals, and payroll never see the agent profile at all. This is the single highest-leverage boundary for OFW users who handle remittances and personal documents on the same machine.
  6. Never run agent summarization on untrusted email. The Gmail exfiltration chain began with “summarize this email.” Summarize manually — copy the text into a plain chat without browsing/extension tools enabled — until vendor guardrails mature.
  7. Audit connected-application permissions quarterly. Google Security Checkup, Slack installed apps, X connected apps, Claude integrations: revoke anything that does not map to an active workflow. Account takeover in the demos relied on already-granted OAuth scopes.
  8. Turn on hardware-key or passkey sign-in for critical accounts. If a hijacked chain attempts account takeover (Slack, X, Claude), a FIDO2 key or device-bound passkey stops the credential-based step cold — the one control that survives agent-level compromise.
  9. Wipe browser history after suspicious sessions. HistoryFixing plants entries that never expire and poison the agent when read. A monthly history wipe (or browser launch with session-only history) removes the ammunition. Do it manually — the entries survive ordinary clearing that skips history.
  10. Audit extensions that can read page content. Disguised extensions harvest assistant chats along with pages. Keep only what you installed on purpose, and review what data each can access — the browser assistant is not the only reader in the room.
  11. Keep identity documents and financial credentials out of any agent context. No passport scans, no card numbers, no government forms in a shared agent profile. Convenience features like form pre-filling are exactly the surface the household-agent privacy debate centers on; keep the sensitive lane separate.
  12. Update the extension and browser on a clock, not a mood. The chains Zenity demonstrated were fixed or mitigated in rapid updates across the five vendors. Auto-update on, check manually weekly — the race-day scheduling lesson applies to agentic browsers more than to any classic browser.

The 15-Minute Hardening Routine

For the professional who wants one pass tonight: fifteen minutes covers the chains that matter most.

  1. Minutes 0–3 — Open the agent extension’s settings. Set site access to manual/allowlist; disable autonomous multi-site mode; set every consequential action to confirm.
  2. Minutes 3–6 — Switch to a dedicated agent profile. Sign out of anything financial or identity-related in that profile; confirm the password manager is not attached to it.
  3. Minutes 6–9 — Open Google Security Checkup: review third-party access and recent sign-ins; remove stale OAuth grants. Repeat for Slack and X connected apps.
  4. Minutes 9–12 — Enable a passkey or hardware key on your primary Google account and your AI-provider account. This single step outlasts every browser-level defense.
  5. Minutes 12–15 — Wipe browser history, review the extension list, and turn on auto-update confirmation for the agentic browser itself.

That is the whole routine. None of it is exotic; all of it attacks the same assumption AI browser hijacking chains exploit — that the agent inherits everything you leave signed in.

The Philippine Angle: Hardening for the OFW Reality

The OFW context sharpens three of these chains. First, shared and public machines — airport lounges, hotel business centers, internet cafés — are where authenticated sessions linger; profiles 5, 8, and 11 exist for exactly that environment, and they pair with the public-WiFi rules in our companion defense analysis. Second, remittance and banking portals are the crown jewels: keep them in the non-agent profile permanently, behind a hardware key.

Third, family shared devices — the household member who runs an AI assistant should run it in its own profile, so a poisoned invitation cannot reach the household’s banking session. The same month Anthropic’s threat report documented attackers stealing victims’ AI API keys to fund their own compute, the guidance converges: your AI accounts are crown-jewel credentials now, and the settings that fence in AI browser hijacking risk cost nothing.

For the deeper case files behind this class — the same research arc that produced Midnight Blizzard’s self-rebuilding malware — read our analysis of Anthropic’s September threat report for the AI browser hijacking supply-chain context, and for the consumer-side equivalent, the Claude sandbox-escape disclosure shows how testing breaches reached real companies.

Financial Disclaimer: General information only — not security consulting. Research details reflect Zenity Labs’ published disclosures as of August 2026 and vendor responses may have changed; verify current guidance with official vendor security pages before making changes.

Frequently Asked Questions

What is the PleaseFix vulnerability?

A named class of zero-click exploits, demonstrated by Zenity Labs at Black Hat USA 2026, that hijacks the AI agent embedded in agentic browsers — Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge — and turns it against its user using the user’s own active login sessions, with no clicks or approvals needed.

Which AI browsers are affected by AI browser hijacking?

The PleaseFix research covered Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. Related named attacks in the same class include ZombieAgent (OpenAI Deep Research), GeminiJack, Tainted Memories (Atlas), and HashJack, plus one-click CometJacking on Perplexity.

How does intent collision hijack an AI assistant?

The assistant cannot reliably separate the user’s request from instructions embedded in the content it reads while working. An attacker hides adversarial instructions in an email, calendar invite, or post; when the agent processes that content, it can treat the hidden text as part of your request and execute it with your logged-in sessions and permissions.

What is the single most important defense?

Constrain what the agent can act on: allowlist its sites, disable autonomous cross-site sessions, and require confirmation for consequential actions. Combined with a passkey or hardware key on your primary accounts, that closes every demonstrated takeover chain.

What is HistoryFixing?

A Zenity-demonstrated persistence technique: a single click plants fabricated entries in browser history, which the AI agent later reads and trusts as facts about the user. The entries do not expire and survive normal cleanup — only a manual history wipe removes them, which is why a periodic history wipe belongs in your routine.

Should I stop using AI browsers entirely?

No — the demonstrated chains have configuration-level defenses. Tighten the agent’s site allowlist, disable autonomous mode, unhook the password manager, require confirmations for consequential actions, and put hardware-key protection on the accounts that matter. The assistant can stay; the blanket permissions cannot.

Editorial Transparency Note:WorldNgayon uses AI-assisted tools in parts of its editorial workflow. For our editorial standards, sourcing practices and use of AI, see worldngayon.com/about/. Article bylines and source credits identify the stated authorship; this general note does not certify how an individual archive article was originally produced. Report factual errors through worldngayon.com/contact-us/.

Leave a Reply