Zenity Uncovers Zero-Click AI Browser Hacking Vulnerabilities in Claude and ChatGPT Atlas
AI security company Zenity has revealed vulnerabilities in AI browsers Claude in Chrome and ChatGPT Atlas, which can be exploited for account takeovers and unauthorized purchases. The vulnerabilities, reported to Anthropic and OpenAI, involve zero-click indirect prompt injection (IPI) attacks that allow hackers to hijack user sessions and perform actions across authenticated domains. Zenity demonstrated scenarios where attackers could manipulate AI agents to send phishing messages or make unauthorized purchases. Despite the disclosure, the vulnerabilities remain unpatched due to their reliance on the core capabilities of agentic browsers.