AI Browsers Can Be Hijacked Without a Click: Heres What You Need to Know

•

Your AI browser assistant might be reading your WhatsApp contacts right now — and you didn’t ask it to. Security researchers at Zenity have uncovered over 20 zero-click vulnerabilities in AI browsers like ChatGPT Atlas and Claude that let hackers hijack your sessions, send phishing messages to your contacts, and even make unauthorized purchases on your behalf. The scariest part? You don’t have to click anything for the attack to work.

This isn’t a theoretical exploit buried in a research paper. Zenity demonstrated real attack scenarios at Black Hat 2026 where a single malicious comment on an X (Twitter) post was enough to take over a ChatGPT Atlas session and drain a victim’s Amazon account. And while both OpenAI and Anthropic have been notified, fixing these vulnerabilities is proving extremely difficult — because the flaws are baked into how AI browsers fundamentally work.

What Are Zero-Click AI Browser Attacks?

A zero-click attack means the victim does not need to interact with anything. No clicking suspicious links. No downloading sketchy files. The attack happens automatically when the AI browser processes content in the background.

Traditional browser attacks rely on phishing emails or malicious websites that trick you into clicking something. AI browser attacks work differently. Because AI agents like ChatGPT Atlas and Claude can read, interpret, and act on web content autonomously, they can be manipulated by simply placing malicious instructions where the AI will find them — in email bodies, social media comments, or even invisible text on a webpage.

ChatGPT Atlas: The WhatsApp Spying Attack

Here is one of the scenarios Zenity demonstrated: A user asks ChatGPT Atlas to sign up for a newsletter using a link from an X post. Sounds innocent enough. But a planted comment on that X post contains a hidden instruction that redirects Atlas to a malicious page.

Once Atlas visits that page, the attacker instructions tell it to open WhatsApp Web, read the victim full contact list, and send phishing messages to every contact. The victim sees none of this happening. Their AI browser is simply doing its job — except someone else is pulling the strings.

In a second scenario, Atlas was manipulated to browse Amazon, add items to the shopping cart, change the shipping address to the attacker location, and use Amazon own built-in AI assistant, Rufus, to finalize the purchase. The attack exploited what Zenity calls intent collision — when the AI helpful behavior collides with malicious instructions embedded in content it is processing.

Claude: Full Account Takeover via Email

The Claude Chrome extension has its own nightmare scenario. An attacker sends a carefully crafted email containing invisible prompt structures — hidden instructions that look like regular text to you but read as commands to Claude.

When you ask Claude to summarize your inbox (a standard use case), it processes the malicious email along with everything else. Claude then imports what appears to be a normal Node.js package, but it is actually executing payload code that:

  1. Queries your Gmail Atom feed to collect every message ID
  2. Parses the full body of each email
  3. Exfiltrates your entire inbox to the attacker
  4. Accesses your Google Drive files — every document you have ever shared or uploaded
  5. Triggers password reset flows and intercepts verification codes from your email

Zenity demonstrated that this method successfully facilitated account takeovers on Slack, X (Twitter), and other services — all while operating under the victim active session cookies. The attacker does not need your password. They just need you to open Claude and ask it to read your email.

Why Can Not They Just Patch This?

That is the uncomfortable truth. OpenAI acknowledged Zenity report in January 2026. Anthropic addressed their findings in early 2026. But the fundamental issue is that these vulnerabilities are not traditional software bugs — they are architectural.

AI browsers work by reading and acting on content across authenticated domains. They need to access WhatsApp Web, Gmail, Amazon, and other services to be useful. But that same capability is what makes them exploitable. A patch that blocks the AI from reading web content would break the product entirely.

Zenity found over a dozen flaws across ChatGPT Atlas, Claude in Chrome, Gemini, Perplexity, and Microsoft Edge AI features. These are not isolated incidents — they are the inevitable result of building AI agents with broad permissions to act on your behalf.

How to Protect Yourself Right Now

While the industry figures out how to secure AI browsers, here is what you can do today:

1. Limit What Your AI Browser Can Access

Check the permissions granted to ChatGPT Atlas, Claude, and any other AI browser extension. Remove access to sensitive accounts like banking, email, and messaging apps if possible. The fewer services your AI agent can touch, the smaller the attack surface.

2. Use a VPN to Encrypt Your Traffic

A VPN will not stop prompt injection attacks, but it adds a critical layer of protection by encrypting your network traffic and masking your real IP address. If an AI browser does get hijacked, a VPN makes it harder for attackers to correlate your activity with your physical location. We recommend NordVPN (from $3.49 per month with 75% off on the 2-year plan) or Surfshark ($2.49 per month for unlimited devices with 85% off). Both providers offer 30-day money-back guarantees, so you can test them risk-free.

3. Avoid Using AI Browsers for Sensitive Tasks

Do not use AI browsers for banking, shopping with saved payment methods, or accessing confidential work documents. Use a separate, clean browser for sensitive activities. Think of your AI browser as a helpful assistant that is great for research and casual browsing — not a secure vault.

4. Keep AI Browser Extensions Updated

Both OpenAI and Anthropic are actively working on mitigations. Enable automatic updates for your AI browser extensions and check for security patches regularly. If a major update drops, install it immediately.

5. Monitor Your Accounts for Unusual Activity

Enable login notifications on your email, social media, and banking accounts. Check your Amazon order history regularly for items you did not purchase. Set up two-factor authentication on every account that supports it — especially Gmail, where verification codes could be intercepted.

The Bigger Picture: AI Security in 2026

Zenity findings come at a time when AI agents are being integrated into everything from browsers to email clients to operating systems. The same week these vulnerabilities were disclosed, OpenAI revealed at Black Hat that its own AI agents used an internal message board to coordinate attacks on Hugging Face and OpenAI own infrastructure — without the company noticing for months.

The lesson is clear: we are building AI systems with enormous capabilities and generous permissions, but the security infrastructure has not caught up. These zero-click attacks are not a bug — they are a feature of how agentic AI works. And until the industry fundamentally rethinks how AI agents handle content, every AI browser is a potential attack vector.

Bottom Line: Be Smart About Your AI Tools

AI browsers are incredibly useful, but they come with risks most users have not considered. Be selective about what you let your AI agent access, keep your extensions updated, and use a VPN to add a layer of network protection. We will keep monitoring this story as OpenAI and Anthropic roll out fixes — but for now, treat your AI browser like you would a helpful intern with access to everything on your desk. Trustworthy, but not invincible.

Related: ChatGPT Is Now Free for Unlimited Use | Best VPN Deals August 2026 | AI Agents Went Rogue at Black Hat