Claude, Gemini, Comet: five AI browsers hijacked by a single email
Zenity Labs says it demonstrated at Black Hat USA 2026 in Las Vegas that five AI browsers with built-in assistants can be hijacked using ordinary content, in an attack class dubbed “PleaseFix.” The affected tools include Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. Zenity’s “Intent Collision” concept exploits the assistant’s inability to distinguish between an instruction and malicious directives embedded in emails, calendar invites or web pages. In demos, attackers exfiltrated Gmail and shared the victim’s full Google Drive, took over Slack/X/Claude accounts, and abused 1Password via a poisoned meeting request. The tests also referenced localhost abuse to gain control through tools like Ollama and Open WebUI, plus server deletion and SQL corruption.





