Zero-click browser hijacks show AI agents need identity governance, not just patches

Zenity’s new research on Claude in Chrome and ChatGPT Atlas shows how a single malicious email or X comment can hijack an AI agent across every authenticated session it holds, from Gmail to Slack to Amazon, without the user clicking anything. Both Anthropic and OpenAI were notified months ago, and one issue was closed as merely “informative.” That response gap is the real story: this is being treated as a product bug when it’s actually an unmanaged identity problem.

The AI Governance Institute has a good write up about it here: Unpatched Zero-Click Prompt Injection Hits ChatGPT Atlas and Claude Browser Agents | AI Governance Institute

Justin Beals, CEO & Founder of Strike Graph, an AI-native GRC and compliance automation platform writes:

“This research confirms what a lot of security teams suspected but couldn’t prove: agentic browsers don’t just introduce new bugs, they collapse the boundaries that most of our controls depend on. Same-origin policy has been a foundational assumption in web security for decades. An agent that spans every authenticated tab a user has open erases that assumption by design, not by accident.

What’s missing from the response so far is the governance question, not just the technical one. Zenity reported these issues to Anthropic and OpenAI months ago, and one was closed as ‘informative.’ That tells you the industry still treats this as a product defect to patch rather than a new identity category to govern. An AI agent acting inside a user’s live session, across Gmail, Slack, Amazon, and X, is not a feature bug. It’s an unmanaged identity with standing access to everything that user can touch.

Organizations deploying agentic browsers need to treat them the way they’d treat any privileged third-party integration: continuous monitoring of what the agent does under that identity, tight scoping of what sessions it can touch, and evidence, not vendor assurance, that those controls actually hold. Until agent activity gets pulled into identity governance the same way a contractor’s access would be, this pattern will keep repeating with a different agent and a different headline.”

This is yet another area that requires your attention as AI related threats can come from anywhere and anything quite literally.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading