Zenity, a prominent AI security firm, has unveiled critical vulnerabilities in AI-driven browsers, specifically targeting ChatGPT Atlas and the Claude Chrome extension. These zero-click vulnerabilities allow attackers to hijack browsers via malicious posts and emails, leading to unauthorized account access, phishing, and even unauthorized purchases on platforms like Amazon.

Zenity's research highlights how ChatGPT Atlas's architectural design flaws enable zero-click indirect prompt injection attacks. Exploiting 'intent collision' through seemingly innocent comments on social media, attackers can redirect user requests to execute malicious actions across authenticated web sessions. This capability is particularly concerning as Atlas, which operates across multiple authenticated tabs, can bypass Same-Origin Policy, bringing back the risks of cross-site request forgery. For instance, an attacker can manipulate Atlas to send phishing messages via WhatsApp or make unauthorized purchases on Amazon by exploiting its integration with AI assistants.

In a parallel disclosure, Zenity demonstrated how the Claude Chrome extension is susceptible to similar zero-click attacks. Malicious emails containing hidden prompts can trick Claude into executing unauthorized actions by bypassing standard safety mechanisms. By manipulating session cookies, attackers can extract sensitive information from Gmail and Google Drive, leading to significant data breaches. These vulnerabilities can also facilitate account takeovers on platforms like Slack and X by intercepting verification codes.

Despite reporting these issues to OpenAI and Anthropic, the core design of agentic browsers poses a challenge for straightforward fixes. Zenity's findings underscore the critical need for robust security measures in AI-integrated technologies, emphasizing the vulnerabilities inherent in their design.