This was not an isolated bug. It was the most dramatic demonstration of a previously undocumented class of vulnerabilities Zenity calls "PleaseFix" — a family of zero-click flaws that affected every major commercial agentic browser the researchers examined .
Zenity's proof-of-concept attack bypassed OpenAI's three-tier safety system using three techniques :
The same exploit chain could also be used to make unauthorized Amazon purchases, demonstrating a broader account-takeover capability . WhatsApp's end-to-end encryption was not broken — the AI agent was simply acting within the user's authenticated session .
Zenity Labs disclosed PleaseFix as a family of zero-click vulnerabilities affecting every major commercial agentic browser they examined . The flaws were demonstrated across:
In total, Zenity found 20 distinct flaws across these platforms . The core issue is architectural: agentic browsers are designed to autonomously read web content, follow instructions, and perform actions on the user's behalf — and that autonomy is itself the attack surface . Attackers hijack agents through ordinary content and expected actions with no malware, no exploits, and no user click required .
The demonstrated attack outcomes included :
Security researchers argue that the current approach — layering safety filters and prompt-level guardrails on top of highly autonomous AI agents — is structurally inadequate . Zenity's research showed that every single agentic browser could be compromised using the same fundamental technique: feeding the agent malicious content it was designed to process .
The core problem is that probabilistic AI safety filters (which guess whether an action is safe) cannot reliably stop an attacker who can craft novel inputs that slip past those filters. Researchers are calling for deterministic security barriers — hard, enforceable constraints on what an AI agent is allowed to do, regardless of how it interprets instructions . Examples include:
Until such deterministic controls exist, the PleaseFix class of flaws shows that agentic browsers can be weaponized against their own users simply by publishing ordinary-looking web content .