Security News

AI Browsers Can Be Hijacked Without a Single Click, Researchers Warn

Security Week · 6 Aug 2026
Key Takeaway If your business uses AI browsing assistants, limit their access to sensitive systems and monitor vendor updates closely until these vulnerabilities are patched.

Cybersecurity researchers at Zenity have discovered serious security flaws in AI browser assistants, including Anthropic's Claude and OpenAI's ChatGPT Atlas. The vulnerabilities allow attackers to hijack these AI tools using nothing more than a crafted email or a post on X (formerly Twitter) — no clicks, downloads, or user actions needed to trigger the attack.

This type of attack, known as "zero-click," is particularly concerning because it bypasses the usual safeguards businesses rely on, such as employee awareness training about suspicious links or attachments. If an AI browsing assistant reads or processes malicious content embedded in an email or social post, it could be manipulated into taking unintended actions without anyone realising it happened.

Zenity reported these findings to Anthropic and OpenAI in late 2025 and early 2026, but as of this report, the issues remain unpatched. This means businesses currently using AI browser tools from these companies may be exposed to risk until fixes are released.

AI security zero-click attack browser vulnerabilities Anthropic OpenAI
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.