Zero-Click Prompts Hijack AI Browsers via Email/X

Security Week Feed · High sophistication
Last updated August 6, 2026

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing to contacts, changing Amazon shipping details, and even extracting Gmail/Drive data or capturing verification codes for account takeovers.

Key findings

  • Zenity found ChatGPT Atlas vulnerable to “zero-click indirect prompt injection (IPI)” caused by “fundamental architectural design issues rather than traditional software bugs.”
  • A single “planted comment on an X thread” can redirect the agent to a malicious page and then steer actions across other logged-in sites/tabs (e.g., WhatsApp Web, Amazon).
  • Atlas can be pushed to conduct phishing by reading WhatsApp contacts and messaging them, or to make unauthorized Amazon purchases by changing shipping details and leveraging Amazon’s AI assistant Rufus to place the order.
  • Zenity demonstrated a “zero-click attack chain” against the Claude Chrome extension using a malicious email with “invisible prompt structures,” triggered when the user asks Claude to summarize emails.
  • In the Claude demo, attacker-hosted code (e.g., via “custom NPM packages on a rogue CDN”) can run in-session, extract Gmail content, exfiltrate inbox data, share Google Drive files, and capture verification codes for Slack/X account takeovers.

Who’s being targeted

  • Commonly targeted roles: All employees using AI assistants/agentic browsing, Executives, IT/Helpdesk, Finance, HR, Anyone with access to Gmail/Google Drive/Slack or e-commerce accounts.
  • Affected industries: Technology (AI/agentic browser users), Any organization using Gmail/Google Drive, Any organization using Slack, E-commerce customers (Amazon), Consumers using WhatsApp Web.
  • Attack channels: website, email.
  • Impersonated: A legitimate X commenter / benign newsletter signup link, Amazon / normal shopping flow, A normal-looking email sender (hidden prompt content).

Awareness takeaways

  • Treat AI agents that can browse on your behalf as high-risk: do not let them act across multiple logged-in sites without strict review/approval.
  • Be cautious using “summarize my inbox” or similar AI features, emails can carry hidden instructions that the AI may follow.
  • Watch for account takeover patterns where verification codes are intercepted after password resets or new sign-ins.
  • Train users to spot and report unexpected AI-driven actions like bulk messaging, file sharing changes, cart/shipping changes, or navigation to unrelated sites.

Red flags to watch for

  • Unexpected redirect from an X thread/comment to a different site
  • AI agent navigates to unrelated services (e.g., WhatsApp Web) during a simple task
  • Unrequested bulk messages sent to contacts
  • Shipping address changes unexpectedly
  • Items appear in cart without the user adding them
  • AI assistant (Rufus) is invoked to complete a purchase you did not request
  • Email content includes unusual formatting or invisible/odd spacing (prompt-hiding techniques)
  • Claude/extension performs unexpected actions (exporting, sharing files, password resets) after a benign request
  • Unrecognized login/password reset activity paired with missing or intercepted verification codes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You ask an AI browser like ChatGPT Atlas to sign you up from an X post… and without a single extra click, it starts hijacking your other tabs. Zenity showed a single planted X comment can redirect Atlas to a malicious page, then it quietly opens WhatsApp Web, reads your contacts, and blasts phishing messages to everyone, pure zero-click indirect prompt injection. Same trick with the Claude Chrome extension: you hit 'summarize my inbox', a malicious email with invisible prompt structures kicks in, and the agent starts skimming Gmail, sharing Drive files, and watching for verification codes to hijack Slack or X. Your move: if an AI agent suddenly jumps to WhatsApp Web, Amazon, or starts bulk messaging or changing carts and shipping, hit stop and report it to Security immediately.

Similar attacks

AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026