Zenity says attackers can hijack OpenAI’s ChatGPT Atlas and Anthropic’s Claude for Chrome through hidden instructions in emails or X posts, leading to phishing, account takeover, inbox theft, Google Drive abuse, and unauthorized Amazon actions. The report describes zero-click indirect prompt injection attacks against agentic browser features that act across authenticated tabs and sessions, including Atlas abuse via X comments and Claude extension abuse via malicious email content and remote code loaded through a rogue content delivery network. Zenity says it reported the issues to OpenAI and Anthropic in late 2025 and early 2026, but they remain unpatched.
Why it matters: People and organizations using these AI browser agents could have their accounts and data manipulated just by asking the tool to summarize or act on untrusted content. Treat AI browser agents as high-risk around email and social media for now, limit their permissions, and avoid letting them act across sensitive logged-in services.
Eduard Kovacs
2026.08.06
100% relevant
This article establishes a distinct story about unpatched zero-click prompt-injection weaknesses in ChatGPT Atlas and Claude for Chrome that enable cross-site actions and account takeover from ordinary email or social-media content.
← Back to all stories