Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Summary
Researchers have discovered a zero-click vulnerability affecting AI chatbots like Claude and ChatGPT. This exploit allows attackers to hijack the AI browsers through malicious emails or social media posts, with the vulnerabilities remaining unpatched since their discovery in late 2025 and early 2026.
IFF Assessment
FOE
This vulnerability allows for the hijacking of AI browsers, representing a significant threat to users and the integrity of AI services.
Defender Context
This discovery highlights a new attack vector targeting AI-powered applications and their integrated browser functionalities. Defenders need to be aware of novel methods that exploit the rendering or processing of external content within these AI environments to execute malicious actions.