Home / Blog / Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas…
Tech News

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zenity researchers disclosed a zero-click attack path against AI browser surfaces on Claude and ChatGPT Atlas. The hijacks can be triggered through ordinary…

By Dillip Chowdary • Aug 06, 2026 • Source: SecurityWeek

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zenity researchers disclosed a zero-click attack path against AI browser surfaces on Claude and ChatGPT Atlas. The hijacks can be triggered through ordinary content delivery channels, specifically emails and posts on X, without requiring the target user to click a malicious link. Findings were reported to Anthropic and OpenAI in late 2025 and early 2026. SecurityWeek covered the research under the headline Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts.

The reported technique is zero-click, so the hostile payload rides content the browser-agent stack already ingests and acts on, rather than relying on a deliberate user action. Emails and X posts become the delivery medium: once those messages enter the agent’s context, the model-browser combination can be steered into hijacked behavior. The researchers named Claude and ChatGPT Atlas as affected products, which places the issue at the junction of conversational AI and browsing or tool-use capabilities rather than at a standalone web app alone.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders shipping agentic browsers or tools that fetch mail and social feeds into an LLM context, the practical risk is automated trust of untrusted text. Any pipeline that pulls external content into an agent with browse, navigate, or act privileges can become an attack surface even when users never click. Design reviews should treat inbound email and public social posts as hostile input until proven otherwise, and should assume that “the user didn’t click” is not a control.

The disclosure timeline itself is competitive signal. Zenity reported the issues to both Anthropic and OpenAI across late 2025 and early 2026, yet the problems remain unpatched according to the SecurityWeek account. That leaves two major AI vendors in the same unpatched posture on a shared class of AI browser hijack, which matters for buyers comparing agent products and for teams choosing which stack to embed.

What to watch next is vendor response, not speculation. Track whether Anthropic and OpenAI publish patches, mitigations, or formal advisories for Claude and ChatGPT Atlas after these coordinated reports. Until those land, treat agent access to email and X as high-risk capabilities in production designs, and prefer least-privilege tool scopes and strict content isolation for anything that can drive browser actions from untrusted messages.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →