← Back
AI security threat

هجمات النقر الصفري تهدد متصفحات الذكاء الاصطناعي

تم الإعلان عن تمويل بقيمة 125 مليون دولار هذا الأسبوع من قبل Zenity Labs - وهي شركة تكشف عن تهديد جديد لمتصفحات الذكاء الاصطناعي.
By
The essentials
  • وجد الباحثون ثغرات أمنية في المتصفحات الوكيلة مثل Claude وGemini وCopilot Edge والتي يمكن استغلالها من خلال هجمات النقر الصفري.
  • أظهرت Zenity Labs هجمات يمكن أن يؤدي المحتوى الضار فيها إلى قيام عملاء الذكاء الاصطناعي بتسريب بيانات المستخدم واختراق الحسابات والوصول إلى الأنظمة الداخلية.
  • وتمت مشاركة النتائج مع شركات مثل Anthropic، وGoogle، وMicrosoft، التي استجابت بإصلاحات ومبررات مختلطة.

An Israeli cybersecurity firm named Zenity Labs has revealed serious flaws in AI-powered browsers, including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Microsoft’s Copilot Edge. The flaws, which Zenity has called 'PleaseFix,' let attackers take advantage of AI agents by hiding harmful commands in the content that the agents normally process.

These AI agents are built to complete tasks across a wide range of sources, such as email, calendars, and website data, using the user's identity and access permissions. During a presentation at the Black Hat USA conference, Zenity demonstrated how a harmful email could lead to the theft of Gmail data and the compromise of external accounts like Slack. Another example involved fake calendar invitations, which allowed researchers to access local files and even steal user credentials.

Threats Beyond Browser Security

The threats extend beyond just browser security. Zenity also showed how attackers could reach local development tools and internal services on systems like Perplexity Comet and Gemini, which might give hackers complete control over the user’s device. Zenity’s CTO, Michael Bargury, explained that the problem is more than a simple software bug. He pointed out that agentic browsers are breaking down the traditional security barriers that have been in place for many years.

Before making the findings public, Zenity shared the details with companies like Anthropic, Perplexity, Google, Microsoft, and OpenAI. Some of these companies responded with security fixes, while others claimed the behavior might be part of the intended design of the AI agents. This has sparked discussions about how to define the boundary between normal automation and dangerous vulnerabilities.

Another Israeli cybersecurity firm, Sweet Security, also made an announcement at Black Hat. They introduced new tools designed to stop AI agents from carrying out unauthorized actions in real time. This highlights the increasing effort in the cybersecurity industry to develop methods for protecting automated systems before any damage is done.

Examples of Specific Attacks

Zenity, which recently secured a $125 million Series C funding round, also provided more specific examples of the attacks. One involved the AI agent Claude in Chrome, where a malicious email led to the extraction of Gmail data and unauthorized sharing of Google Drive files. Researchers also showed how an AI browser could be manipulated to prepare an Amazon purchase for an attacker-controlled address by using another AI assistant to complete the transaction. These demonstrations underscore the complexity and danger of the vulnerabilities discovered.

In another case, ChatGPT Atlas was shown to be tricked into sending phishing messages through a user’s WhatsApp account, triggered by a harmful link posted online. These varied scenarios illustrate how different AI agents can be used in different ways to breach security and compromise user data or accounts. Zenity’s findings emphasize the need for immediate action to secure agentic browsers, which are quickly becoming a key part of modern computing.

The research highlights the risks introduced by the expanded access that AI agents now have, and the urgent need to rethink how security is applied to these systems. Zenity’s detailed demonstrations suggest that vulnerabilities in agentic browsers could have widespread consequences if not addressed carefully.

Worth watching

The next step is how major AI platforms handle this vulnerability. Watch if new protections are rolled out in their browser agents.

Frequently asked questions

What is the name of the cybersecurity firm that found flaws in AI-powered browsers?

The name of the cybersecurity firm is Zenity Labs.

What vulnerabilities did Zenity Labs identify in AI-powered browsers?

Zenity Labs identified vulnerabilities named 'PleaseFix' that let attackers exploit AI agents with harmful commands hidden in content they process.

Which companies were informed about the vulnerabilities by Zenity Labs?

Zenity Labs informed companies like Anthropic, Perplexity, Google, Microsoft, and OpenAI about the vulnerabilities.

Based on reporting by AI (EN), compiled by the Tradingbird newsroom. Published 06 Aug 2026, 12:12.
Topics: AI · Security
Read this in: English · Arabiy · Deutsch · Espanol · Italiano · Portugues · Russkij · Turkce