Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover
DAY 2
10:40-
11:20
Agentic browsers dismantle decades of hard-won security mitigations by design. Atlas breaks Same-Origin Policy, Gemini and Edge add untethered localhost access, Comet opens your filesystem, and Claude runs scripts on any site. So XSS, sandbox escapes, and drive-by exploitation are back.
We present PleaseFix, the evolution of ClickFix: a vulnerability class targeting agents, and Intent Collision, a universal technique to exploit it. Finally, we detail HistoryFixing, a technique targeting browser history that weaponizes a 16-year-old browser API.
We demonstrate full 0click chains on flagship agentic browsers via social media posts and calendar invites: account takeover of Slack, X, 1Password, and Claude; exfiltration ranging from the local filesystem to Gmail and GDrive; phishing your friends over WhatsApp; exfiltrating your org’s source code; deleting your AWS instances; ordering our hacking gear on your Amazon; and landing a reverse shell for full RCE, escaping the browser sandbox.
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
General
-
-
Share :
Speakers
-
Stav Cohen
スタヴ・コーエン
Stav Cohen is an AI Security Research Team Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world and count as a thought leader in the AI security space.
-
Michael Bargury
マイケル・バーグリー
Michael Bargury is a hacker, builder and a cybersecurity practitioner. He is the co-founder and CTO of Zenity, the first application security company enabling enterprises to empower business users without paying for it in security incidents. He leads the OWASP LCNC Top 10, has a column on DarkReading, and delivers research, tools and talks regularly at top conferences including BlackHat, DEFCON and RSAC.