Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Summary

Researchers have discovered a zero-click vulnerability affecting AI chatbots like Claude and ChatGPT. This exploit allows attackers to hijack the AI browsers through malicious emails or social media posts, with the vulnerabilities remaining unpatched since their discovery in late 2025 and early 2026.

IFF Assessment

FOE

This vulnerability allows for the hijacking of AI browsers, representing a significant threat to users and the integrity of AI services.

Defender Context

This discovery highlights a new attack vector targeting AI-powered applications and their integrated browser functionalities. Defenders need to be aware of novel methods that exploit the rendering or processing of external content within these AI environments to execute malicious actions.

Read Full Story →