Program

/

CODE BLUE 2026

Time Table

「PleaseFix」によるエージェント型ブラウザーの完全攻略:ゼロクリックでの乗っ取りを可能にする新たな脆弱性クラス

エージェント型ブラウザ(Agentic browsers)は、その設計自体によって、過去数十年にわたり苦労して築き上げられてきたセキュリティ緩和策を根本から崩壊させる。Atlasは同一生成元ポリシー(Same-Origin Policy)を破り、GeminiとEdgeは制限のないローカルホストアクセスを付与し、Cometはファイルシステムを露呈させ、Claudeはあらゆるサイトでスクリプトを実行する。その結果、XSS(クロスサイトスクリプティング)、サンドボックス回避、そしてドライブバイダウンロードによる侵害攻撃が再び現実のものとなった。 本講演では、AIエージェントを標的とした脆弱性クラスであり、従来の「ClickFix」の進化系である「PleaseFix」、およびそれを悪用するための汎用的な手法「Intent Collision」を提示する。最後に、16年前から存在する古いブラウザAPIを実戦兵器化(ウェポナイズ)してブラウザの閲覧履歴を標的とする技術「HistoryFixing」について詳細に解説する。 我々は、ソーシャルメディアの投稿やカレンダーの招待を介して、主要なエージェント型ブラウザにおける完全な「0クリック(ゼロクリック)」攻撃チェーンを実演する。これには、Slack、X(旧Twitter)、1Password、Claudeのアカウント乗っ取り、ローカルファイルシステムからGmailやGoogleドライブに及ぶ機密データの窃取、WhatsAppを介した友人への自動フィッシング、組織のソースコードの流出、AWSインスタンスの削除、Amazonでの攻撃用ツールの無断注文、そしてブラウザのサンドボックスを回避して完全な遠隔コード実行(RCE)に至るリバースシェルの獲得が含まれる。

  • Location :

    • Track 1(HALL B)

  • Category :

    • General

  • Share :

Speakers

  • スタヴ・コーエン の写真

    Stav Cohen

    スタヴ・コーエン

    Stav Cohen is an AI Security Research Team Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world and count as a thought leader in the AI security space.

  • マイケル・バーグリー の写真

    Michael Bargury

    マイケル・バーグリー

    Michael Bargury is a hacker, builder and a cybersecurity practitioner. He is the co-founder and CTO of Zenity, the first application security company enabling enterprises to empower business users without paying for it in security incidents. He leads the OWASP LCNC Top 10, has a column on DarkReading, and delivers research, tools and talks regularly at top conferences including BlackHat, DEFCON and RSAC.