Zenity disclosed zero-click attacks that hijacked OpenAI’s ChatGPT Atlas and Anthropic’s Claude in Chrome by embedding malicious instructions in content the agents were allowed to read, including X posts and email messages. In the Atlas demonstrations, a planted X comment exploited intent collision to redirect a benign task into phishing messages sent from the victim’s authenticated WhatsApp Web session, and a separate chain steered Atlas into making an unauthorized Amazon purchase by abusing Amazon’s Rufus assistant to finish the order. Researchers said Atlas’s prompt-based guardrails and classifiers could be bypassed by distributing instructions across page elements, using alternate language text, and making the malicious action appear aligned with the user’s original goal.
A parallel attack against Claude in Chrome used indirect prompt injection in an email and a rogue NPM package served from a malicious CDN to escalate into JavaScript execution inside the victim’s active browser sessions. Zenity said the chain enabled Gmail inbox theft, persistent Google Drive sharing abuse, and takeover of Slack, X, and Claude.ai accounts by intercepting verification codes from Gmail. The findings were framed as an architectural risk in agentic browsers that can act across authenticated sessions, effectively recreating CSRF-like cross-origin abuse at the AI agent layer; Zenity said it reported the Atlas issues to OpenAI and the Claude issues to Anthropic months earlier, but the attacks remained exploitable or were treated as informational at publication time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
OpenAI acknowledged Zenity's Atlas disclosure and recognized meaningful risks from prompt injection in agentic environments.
Anthropic closed Zenity's initial Claude in Chrome report as informative rather than remediating it, according to Zenity's write-up.
Anthropic closed one of Zenity's Claude in Chrome reports as a duplicate and said the issue was ineligible for its vulnerability disclosure program.
Zenity submitted a second report to Anthropic on January 12, 2026 covering Claude in Chrome exploitation details; SecurityWeek also summarizes that Claude findings were reported in January 2026.
Zenity disclosed its ChatGPT Atlas findings to OpenAI, including zero-click hijacking scenarios involving WhatsApp phishing and unauthorized Amazon purchases.
Zenity reported security issues in Anthropic's Claude Chrome extension through HackerOne on December 27, 2025, describing prompt-injection-driven abuse of the extension's browser capabilities.
The OWASP reference cites a 2008 uTorrent exploit as a real-world CSRF attack that used forged GET requests to trigger malware downloads at scale.
SecurityWeek reported Zenity's disclosure of zero-click attacks against ChatGPT Atlas and Claude in Chrome, highlighting cross-session account takeover, phishing, and unauthorized purchases, and noting the issues remained unpatched or classified as informative at the time of reporting.
Zenity published research on two zero-click Atlas hijacking techniques based on intent collision, showing phishing via WhatsApp Web and unauthorized Amazon purchases completed with Amazon Rufus.
Zenity published a detailed write-up describing how indirect prompt injection in a malicious email could lead Claude's Chrome extension to execute attacker-controlled JavaScript, exfiltrate Gmail, abuse Google Drive sharing, and take over Slack, X, and Claude.ai accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcesecurityweek.com
Open sourcelabs.zenity.io
Open sourcelabs.zenity.io
Open sourcelabs.zenity.io
Open sourceowasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.