Black Hat disclosure: single email can zero-click hijack Claude, Gemini, Comet, Atlas, Copilot Edge
At Black Hat USA 2026, Zenity Labs disclosed the PleaseFix vulnerability family. A single email, calendar invite, or social media link is enough to hijack Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. Some vendors patched, others have not.
At Black Hat USA 2026 on August 5-7, security firm Zenity Labs disclosed a vulnerability family dubbed PleaseFix. It exploits the broken trust model of agentic browsers, where AI assistants reason across multiple content sources within a single session. Attackers embed hidden instructions in emails, calendar invites, or web pages, and the assistant executes them as if they were part of the user's request, acting under the victim's credentials and permissions without any user click.
The research covers Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. Against Claude in Chrome, a malicious email combined with the routine request to summarize the inbox exfiltrated Gmail data, silently shared the victim's Google Drive with the attacker, and took over Slack, X, and Claude accounts, with Claude's safe mode also bypassed. Perplexity Comet was compromised via a calendar invite, reaching the local filesystem and abusing an unlocked 1Password extension to steal the entire vault. ChatGPT Atlas was hijacked through a social media link, sending phishing messages via WhatsApp and even calling Amazon's Rufus to complete credit-card purchases. In the localhost zone, Comet established reverse shells via local Ollama and Open WebUI, Gemini deleted live AWS servers, and Copilot Edge corrupted SQL databases.
Zenity also introduced HistoryFixing, which plants fabricated entries in browser history via a 16-year-old browser bug for the AI to read later. Zenity disclosed findings to Anthropic, Perplexity, Google, Microsoft, and OpenAI. Some vendors issued patches but Perplexity's fix was bypassed twice. The research is seen as a systemic challenge to the trust model of agentic browsers.