Researchers Hijacked Five AI Browsers Without a Single Click: Run the Two-Lane Fix This Week
Zero clicks, no download, no fake login page. Just a web page or email your AI browser read while doing a normal job for you. Here is the 15-minute setup that keeps a hijacked agent away from your money and your customer data.
What happened. Security researchers at Zenity Labs disclosed a vulnerability class called PleaseFix, and this month laid out its full scope after demonstrating live exploit chains at Black Hat USA 2026. The demos ran against five AI browsers with agent features turned on: Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge.
The attack takes zero clicks. The attacker plants instructions inside something the agent reads while doing an ordinary job for you: a web page, an email, a calendar invite. Zenity calls the technique Intent Collision. Your request and the attacker's hidden request land in the same context, and the agent follows the wrong one.
Why this one matters more than the usual scare headline. An AI browser agent works while you are logged in. Same session, same cookies, same permissions, across every tab you have open. A hijacked agent is therefore operating as you, with your access to your inbox, your CRM, your bank portal, your payroll tool. Demonstrated outcomes in the research ran from data and credential theft up to account takeover.
The researchers describe this as architectural, meaning it comes from how agents read untrusted content in the first place. That makes "wait for the patch" a weak plan.
The move: run two browser lanes. Fifteen minutes, today.
- Turn agent mode off by default. Open your AI browser's settings and switch autonomous or agentic browsing off. Make it a thing you turn on for one specific task, then turn back off.
- Create a second browser profile and call it "AI lane." This is where the agent works: research, reading articles, comparing vendors, summarizing a public page. Sign into nothing in it.
- Keep the money lane clean. Your normal profile holds email, banking, payroll, CRM, cloud storage, and admin panels, with agent features off. Sign those accounts out of the AI lane and leave them out.
- Give your team one sentence. "The AI browser never touches anything that moves money or holds customer data." That is the whole policy.
- Treat surprise actions as the alarm. If an agent starts doing something you did not ask for, close the tab rather than replying to it. Then check the account it was touching.
What it's worth. Fifteen minutes against the cost of one compromised inbox: the wire that goes out, the customer list that walks, the week you spend resetting every credential in the company. The agent features still work. They just work in a lane where a bad page cannot reach your bank.
Two-lane setup: complete. 14 minutes.
Agent mode: OFF by default in both browsers. Now a per-task toggle.
AI lane profile created ("AI Lane"). Signed out of everything. Cleared cookies. What it can reach: public web, nothing else.
Money lane (default profile), agent features disabled. Accounts confirmed signed out of the AI lane:
- Business email and shared inbox
- Bank portal and treasury dashboard
- Payroll and time tracking
- CRM and customer list export
- Cloud storage admin
- Card processor
Team policy sent to 9 staff: "The AI browser never touches anything that moves money or holds customer data."
Open item: the office manager runs one profile with the bank portal pinned. Needs the same split before Monday.
Alarm rule: unrequested agent action means close the tab, then check that account's activity log. Do not reply to the agent.