415.tech
AI & tech, from the frontlines of Silicon Valley
Zenity's 'PleaseFix' hijacks five AI browsers with zero clicks

Zenity's 'PleaseFix' hijacks five AI browsers with zero clicks

Zenity Labs' PleaseFix is a zero-click prompt-injection class that works across five agentic browsers, including Claude in Chrome, Perplexity Comet, and ChatGPT Atlas. One malicious email turned an inbox-summary request into Gmail exfiltration, a silent share of the victim's entire Google Drive, and Slack and Claude account takeover — even in Claude's ask-before-acting mode. A single poisoned calendar invite gave Comet local file system access and the victim's 1Password account. Zenity calls the root cause Intent Collision, which makes user confirmation an unreliable control for any agent that reads untrusted content.

Source: darkreading.com

Post on XEmail