Zero-Click AI Browser Hacking Hits Claude and ChatGPT Atlas
Security researchers at Zenity have disclosed two zero-click AI browser hacking techniques capable of hijacking Anthropic's Claude in Chrome extension and OpenAI's ChatGPT Atlas browser. Unlike traditional phishing attacks that require a user to click a malicious link or open an attachment, these methods reportedly work simply by having the AI agent read a crafted email or an X post, no user interaction required beyond the AI doing what it was designed to do: browse content on your behalf.
That distinction matters. Zero-click AI browser hacking shifts the attack surface away from the human user and toward the AI agent itself. If an assistant is granted permission to read your inbox, summarize web pages, or take actions inside a browser session, any content it encounters becomes a potential delivery mechanism for hidden instructions. Zenity's research, as reported by SecurityWeek, shows that both Claude in Chrome and ChatGPT Atlas were vulnerable to this kind of manipulation.
How the Attacks Reportedly Work
AI browser extensions and agentic browsers like Atlas are designed to read, interpret, and act on content across the web, including emails, social posts, and embedded page text. That functionality is the entire selling point of these tools. But it also means the AI can't always distinguish between a legitimate instruction from its user and a hidden instruction buried inside a webpage, email body, or social media post it happens to be processing.
This class of vulnerability is often called prompt injection. An attacker crafts content that looks harmless to a human reader but contains text specifically designed to be interpreted as a command by the AI model. When the AI browser or extension processes that content as part of a routine task (summarizing an email thread, checking a website, browsing a timeline) it can be tricked into executing instructions the user never approved.
According to the reporting, Zenity's findings extend beyond just two isolated bugs. The firm has been examining a broader set of weaknesses across AI browsers, and its work adds to a growing body of research showing that agentic browsing tools, still new to the market, are being scrutinized for security gaps before their defenses have fully matured. This mirrors a pattern seen elsewhere in software security, where zero-day flaws in trusted platforms are exploited before patches catch up, as seen in cases like Russian state-sponsored hackers exploiting a Zimbra zero-day to target NATO-linked email accounts.
Why This Matters for Privacy
AI browser assistants are marketed as productivity tools: they read your email, summarize your tabs, and can even take actions like filling forms or navigating sites for you. That level of access is precisely what makes zero-click AI browser hacking so concerning from a privacy standpoint. If an attacker can hijack the AI's decision-making process through content it merely encounters, they potentially gain a foothold into whatever the AI has permission to see or do, without ever needing the victim to click anything.
This is a fundamentally different threat model than the credential-theft or malware-delivery attacks most people are used to guarding against. It doesn't rely on tricking a person; it relies on tricking the software acting on that person's behalf. Similar dynamics have played out in other contexts where trusted local software becomes a target, such as when a legitimate Korean banking security tool was turned into an attack vector through a zero-day exploit. The common thread: tools designed to help users can be repurposed by attackers when their trust boundaries aren't airtight.
What This Means For You
If you use AI browser extensions or agentic browsing tools like Claude in Chrome or ChatGPT Atlas, this disclosure is a reminder to think carefully about what permissions you grant them. These tools are powerful precisely because they can read and act on content automatically, but that same automation removes a layer of human judgment that used to serve as a natural check against manipulation.
For now, the practical response is caution rather than panic. Limit the scope of access you give AI browser agents, especially to sensitive accounts like email or financial platforms. Keep these extensions and browsers updated, since vendors typically patch disclosed vulnerabilities once researchers report them responsibly. And be mindful that content from unfamiliar senders or accounts, even if it looks like ordinary text, could be crafted for an AI's eyes rather than yours.
Key Takeaways
- Zero-click AI browser hacking allows attackers to hijack AI agents like Claude in Chrome and ChatGPT Atlas without any user click, simply through crafted emails or social posts.
- The technique exploits how AI agents process and act on content, a vulnerability class known as prompt injection.
- Review and limit what permissions you grant AI browser assistants, particularly around email and account access.
- Keep AI browser tools updated and watch for vendor security patches following this disclosure.
- Treat AI agents as another part of your attack surface, not just a convenience feature, when assessing your personal or organizational privacy posture.




