AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Attackers can hijack AI browser agents via malicious instructions hidden in content, a zero-click vulnerability dubbed "PleaseFix" for which no simple fix exists.

Attackers can hijack AI browser agents without any user interaction using a vulnerability dubbed "PleaseFix." Hidden malicious instructions within content supplied to the browser allow zero-click takeover. There is no straightforward patch available for this flaw. The attack exploits how AI agents process and act on external data, turning benign inputs into commands that compromise the agent's control. Researchers warn that the threat is difficult to mitigate because it targets the fundamental behavior of AI-driven browsing. Until a fix emerges, users and developers must rely on careful content vetting and input sanitization to reduce risk.