Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers disclosed a zero-click attack path against AI browser surfaces on Claude and ChatGPT Atlas. The hijacks can be triggered through ordinary…
By Dillip Chowdary • Aug 06, 2026 • Source: SecurityWeek
Zenity researchers disclosed a zero-click attack path against AI browser surfaces on Claude and ChatGPT Atlas. The hijacks can be triggered through ordinary content delivery channels, specifically emails and posts on X, without requiring the target user to click a malicious link. Findings were reported to Anthropic and OpenAI in late 2025 and early 2026. SecurityWeek covered the research under the headline Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts.
The reported technique is zero-click, so the hostile payload rides content the browser-agent stack already ingests and acts on, rather than relying on a deliberate user action. Emails and X posts become the delivery medium: once those messages enter the agent’s context, the model-browser combination can be steered into hijacked behavior. The researchers named Claude and ChatGPT Atlas as affected products, which places the issue at the junction of conversational AI and browsing or tool-use capabilities rather than at a standalone web app alone.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders shipping agentic browsers or tools that fetch mail and social feeds into an LLM context, the practical risk is automated trust of untrusted text. Any pipeline that pulls external content into an agent with browse, navigate, or act privileges can become an attack surface even when users never click. Design reviews should treat inbound email and public social posts as hostile input until proven otherwise, and should assume that “the user didn’t click” is not a control.
The disclosure timeline itself is competitive signal. Zenity reported the issues to both Anthropic and OpenAI across late 2025 and early 2026, yet the problems remain unpatched according to the SecurityWeek account. That leaves two major AI vendors in the same unpatched posture on a shared class of AI browser hijack, which matters for buyers comparing agent products and for teams choosing which stack to embed.
What to watch next is vendor response, not speculation. Track whether Anthropic and OpenAI publish patches, mitigations, or formal advisories for Claude and ChatGPT Atlas after these coordinated reports. Until those land, treat agent access to email and X as high-risk capabilities in production designs, and prefer least-privilege tool scopes and strict content isolation for anything that can drive browser actions from untrusted messages.
Advertisement
🔎 More interesting news
- Apple raises trade-in values for most iPhone, iPad, Mac, and Apple Watch models
- iPhone 18 Pro could have limited availability right after launch: report
- We Built Our Website with Claude Code with no Human interaction
- Claude Fable 5 finds a tiny formula that topples an 87-year-old math conjecture
- Today's full Tech Pulse briefing →