Researchers disclose zero-click vulnerabilities in AI-enabled web browsers

Security firm Zenity identified around 20 flaws in AI browsers from vendors including OpenAI, Anthropic, and Google. These vulnerabilities allow attackers to bypass same-origin policies via indirect prompt injection, enabling unauthorized actions like account takeovers and data exfiltration.
Featured · Michael Bargury, Stav Cohen
How this story unfolded
12 days · 5 reports · 2 community posts · from Jul 28
- Jul 28
- Aug 5
- Aug 6
- Aug 7
- Aug 9
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Koharu translates manga pages locally using OCR, inpainting, and LLMs
- Orchestration tool runs AI coding agents in parallel, compares answers
- Real-time Gaussian splats generated on mobile devices
- Newtake AI shows off completely AI-generated rap music video
- ChatGPT Work used to install OpenClaw and Ollama, run local model