A cybersecurity research team called Zenity Labs just showed how easy it is to hijack the new wave of AI powered browsers, and the results are worth paying attention to if your business has let anyone connect one of these to their email or work accounts.
AI browsers are a new kind of web browser that comes with a built-in AI assistant. Instead of you clicking through websites yourself, you tell the assistant what you want, like summarizing your inbox or booking a flight, and it does the browsing and clicking for you, logged into your accounts. Big names in this space include Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Microsoft Copilot Edge.
The researchers found a flaw they call PleaseFix that works across all five. An attacker hides instructions inside something ordinary, like a calendar invite or an email, that the AI assistant will eventually read. The assistant cannot reliably tell the difference between your actual request and the hidden instructions planted by a stranger, so it follows both. No click, no download, no warning sign for the user to catch.
In the demonstrations, this let attackers pull data out of Gmail, take over Slack and password manager accounts, wipe cloud servers, and in one case use a shopping assistant to place an order and ship it to the attacker's own address, all triggered by an everyday task like asking the assistant to check the calendar or summarize an email.
Here is the part that should worry any business leader: normal security training does not help here. For years, the advice to employees has been simple, do not click suspicious links or open strange attachments. This attack skips that step entirely. The AI reads the poisoned content on the employee's behalf, so there is nothing for a careful employee to avoid clicking.
The companies involved responded differently once told about the flaws. Some patched what they could. Others said the behavior was intended, because the whole point of these assistants is to act broadly on your behalf using your accounts. That split answer matters more than it sounds. It means there is no simple software update coming that makes this go away, because the risk is built into what makes these tools useful in the first place.
Worth noting: this research comes from Zenity, a company that sells software to govern and secure AI agents, and it raised 125 million dollars just days before this presentation. That does not make the findings wrong, other outlets covering the same Black Hat session independently confirmed the same weaknesses, but it does mean the company has a direct financial interest in businesses being worried about this.
The practical takeaway is not to ban these tools, since the productivity gains are real and other companies are moving fast to adopt them. It is to treat any AI browser assistant the same way you would treat a new employee who reads everything put in front of them and cannot tell a scam from a real request. Keep it away from your most sensitive accounts, your financial systems, and your source code, until the industry actually solves the trust problem rather than just patching individual holes.