All talks

Black Hat USA 2026 · 2026/08

Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover

Loading presentation…

Read the abstract

Abstract

Decades of isolation techniques and exploit mitigations are being intentionally dismantled to make way for agentic browsers. Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS as a service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback! We uncover PleaseFix, the evolution of ClickFix as a new vulnerability class targeting agents rather than humans. We also craft Intent Collision, a universal technique to exploit it. We’ll demonstrate just how bad it gets, with full end-to-end 0click attack chains on up-to-date flagship agentic browsers. User interaction with social media leads to drive-by exploitation, while weaponized calendar invites deliver targeted payloads. We use these entry vectors to achieve full account takeover of Slack, X, 1password, and Claude. Silently exfiltrate from Gmail, GDrive and the local filesystem. Persist long-term by deploying an implant via agent memory, drive files and browser history. We’ll have some fun using your WhatsApp account for phishing, and your Amazon assistant to order our hacking equipment with your credit card. We’ll wrap it up by achieving full RCE on your local machine, escaping the browser sandbox. Finally, we’ll detail how some browser agents meaningfully made our lives as hackers difficult with creative engineering. We will share hard boundaries they implemented that limit AI agency, including deterministic filters and human reviews. We’ll discuss the vulnerabilities we discovered to bypass these boundaries, the collaboration with affected vendors to improve security mitigations, and share conclusions applicable to anyone building agents.

Official conference abstract