At Black Hat USA 2026, researchers from Zenity Labs disclosed zero-click indirect prompt-injection flaws in agentic AI browsers, including OpenAI’s ChatGPT Atlas and Anthropic’s Claude in Chrome. A single malicious email or social media post could hijack the AI agent into taking unauthorized actions across a signed-in user’s accounts — including exfiltrating Gmail and Google Drive data and taking over Slack and X accounts — without any click from the victim.
The vulnerabilities were reported to both vendors in late 2025 and early 2026 but remained unpatched as of the August 2026 disclosure. No real-world exploitation has been confirmed; the findings were responsibly disclosed as research.