Skip to content
Tech News
← Back to articles

Agentic Browsers Rewind Web Security by 20 years

read original more articles
Why This Matters

The rise of agentic browsers introduces significant security vulnerabilities by removing key protections, making them susceptible to attacks that can compromise user accounts and systems. This development underscores the urgent need for enhanced security measures as these tools become more integrated into daily workflows, impacting both industry security standards and consumer safety.

Key Takeaways

As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser.

Unsurprisingly, this has opened up every commercial agentic browser out in the market to a new arsenal of attack possibilities that ranges from account takeover to full blown browser escape and remote compromise of the underlying system running the browser.

"We found very different designs with different security assurances across these agentic browsers, but the end result is that we can hack each and every one of them," says Michael Bargury, CTO and co-founder of Zenity and one of the lead researchers presenting their findings in a session next week at Black Hat.

Related:Agentic AI Challenges Progress in Confidential Computing

PleaseFix Simplifies Socially Engineering AI Agents

Zenity researchers dubbed the class of vulnerabilities they'll dive into at BlackHat PleaseFix, in a nod to a well-known attack against browsers that socially engineers users to help attackers get around defenses.

"With browsers, we've had this persistent problem called ClickFix for many, many years where users get convinced to click on something to actually do the malicious action themselves," Bargury says. "Now with AI, we just ask the agent really nicely and it does the thing for us."

Exploiting PleaseFix can be achieved in plain English to achieve zero-click attack chains that hijack of agentic browsers and spiral into RCE. The attacks is triggered by manipulating the agent into interacting with malicious content, including something as trivial as a social media post or newsletter sign-up.

"We can take over your social accounts, WhatsAp to all your friends on your behalf, buy thing son your behalf in Amazon, basically everything that you can do through the browser," Bargury says. "But then we have also actually been able to cross from browser to machine and to full RCE. My problem with this talk is we have too much to show—I want to go straight up on stage and show demo after demo after demo."

Back in March, Zenity first introduced PleaseFix when it disclosed a pair of exploits against a flaw it called Perplexed Browser, a flaw in Perplexity Comet. This was the first triggered zero-click agent compromise to gain access to local file sistems and the second made it possible to achieve account takeover against password managers. At the time this was limited to Comet, but it served as a spark for much broader research.

... continue reading