Zenity discloses zero-click hijacking of ChatGPT Atlas and Claude in Chrome

Attackers can hijack benign requests across authenticated sessions via 'intent collision' — a single planted X comment steered Atlas to phish the victim's WhatsApp contacts and purchase items on Amazon via Rufus. Findings were reported to OpenAI and Anthropic but remain unpatched.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Z.ai CEO Jie Tang: GLM 5.3 gains come from RL, not parameter count
- New tool adds 14 skills to Claude Code and Cursor for Markdown diagrams
- Tool turns Claude into a team of AI employees on your Mac
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills