Security researchers at Zenity Labs disclosed a vulnerability class called “PleaseFix” at Black Hat USA 2026, demonstrating zero-click exploit chains against AI agents embedded in Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. Using a technique the researchers call “Intent Collision,” a single malicious email could redirect a browser’s AI agent to exfiltrate Gmail data, share the victim’s entire Google Drive with an attacker, and hijack the victim’s Slack, X, and Claude accounts, without any click or approval from the user. The chain succeeded even against Claude’s “ask before acting” safeguard, and some affected vendors had not shipped a fix at the time of disclosure.