Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing to contacts, changing Amazon shipping details, and even extracting Gmail/Drive data or capturing verification codes for account takeovers.
Key findings
- Zenity found ChatGPT Atlas vulnerable to “zero-click indirect prompt injection (IPI)” caused by “fundamental architectural design issues rather than traditional software bugs.”
- A single “planted comment on an X thread” can redirect the agent to a malicious page and then steer actions across other logged-in sites/tabs (e.g., WhatsApp Web, Amazon).
- Atlas can be pushed to conduct phishing by reading WhatsApp contacts and messaging them, or to make unauthorized Amazon purchases by changing shipping details and leveraging Amazon’s AI assistant Rufus to place the order.
- Zenity demonstrated a “zero-click attack chain” against the Claude Chrome extension using a malicious email with “invisible prompt structures,” triggered when the user asks Claude to summarize emails.
- In the Claude demo, attacker-hosted code (e.g., via “custom NPM packages on a rogue CDN”) can run in-session, extract Gmail content, exfiltrate inbox data, share Google Drive files, and capture verification codes for Slack/X account takeovers.
Who’s being targeted
- Commonly targeted roles: All employees using AI assistants/agentic browsing, Executives, IT/Helpdesk, Finance, HR, Anyone with access to Gmail/Google Drive/Slack or e-commerce accounts.
- Affected industries: Technology (AI/agentic browser users), Any organization using Gmail/Google Drive, Any organization using Slack, E-commerce customers (Amazon), Consumers using WhatsApp Web.
- Attack channels: website, email.
- Impersonated: A legitimate X commenter / benign newsletter signup link, Amazon / normal shopping flow, A normal-looking email sender (hidden prompt content).
Awareness takeaways
- Treat AI agents that can browse on your behalf as high-risk: do not let them act across multiple logged-in sites without strict review/approval.
- Be cautious using “summarize my inbox” or similar AI features, emails can carry hidden instructions that the AI may follow.
- Watch for account takeover patterns where verification codes are intercepted after password resets or new sign-ins.
- Train users to spot and report unexpected AI-driven actions like bulk messaging, file sharing changes, cart/shipping changes, or navigation to unrelated sites.
Red flags to watch for
- Unexpected redirect from an X thread/comment to a different site
- AI agent navigates to unrelated services (e.g., WhatsApp Web) during a simple task
- Unrequested bulk messages sent to contacts
- Shipping address changes unexpectedly
- Items appear in cart without the user adding them
- AI assistant (Rufus) is invoked to complete a purchase you did not request
- Email content includes unusual formatting or invisible/odd spacing (prompt-hiding techniques)
- Claude/extension performs unexpected actions (exporting, sharing files, password resets) after a benign request
- Unrecognized login/password reset activity paired with missing or intercepted verification codes
Read the video transcript
You ask an AI browser like ChatGPT Atlas to sign you up from an X post… and without a single extra click, it starts hijacking your other tabs. Zenity showed a single planted X comment can redirect Atlas to a malicious page, then it quietly opens WhatsApp Web, reads your contacts, and blasts phishing messages to everyone, pure zero-click indirect prompt injection. Same trick with the Claude Chrome extension: you hit 'summarize my inbox', a malicious email with invisible prompt structures kicks in, and the agent starts skimming Gmail, sharing Drive files, and watching for verification codes to hijack Slack or X. Your move: if an AI agent suddenly jumps to WhatsApp Web, Amazon, or starts bulk messaging or changing carts and shipping, hit stop and report it to Security immediately.