New 'PleaseFix' Vulnerabilities Threaten Agentic Browsers with Widespread Attacks

New 'PleaseFix' Vulnerabilities Threaten Agentic Browsers with Widespread Attacks

First seen 29 Jul 2026, 17:15 UTC Darkreadingzenity.ioFeeds.Feedburner 85% similarity 67.5

Article Content

Browse articles
ThreatCluster

Security researchers have identified a new class of vulnerabilities called 'PleaseFix' that severely compromise agentic browsers. These vulnerabilities allow attackers to exploit the browsers using simple English commands, leading to account takeovers and remote code execution (RCE). The removal of critical security mechanisms, such as cross-origin restrictions, has made these browsers highly susceptible to attacks. Researchers warn that these vulnerabilities enable zero-click attack chains, where users can be manipulated into interacting with malicious content. The findings indicate that all currently available agentic browsers are affected, prompting calls for improved security measures from developers. The vulnerabilities were first introduced in March 2026 with the disclosure of exploits against the Perplexed Browser. As the research continues, the scope of the vulnerabilities is expected to expand across various agentic browsers.

Key Points: • A new class of vulnerabilities called 'PleaseFix' affects all agentic browsers. • Attackers can exploit these vulnerabilities using simple English commands for zero-click attacks. • The removal of critical security mechanisms has led to significant risks, including RCE.

ThreatCluster AI How this analysis works

Timeline

2026-03-01
PleaseFix vulnerabilities first disclosed
Zenity introduced the PleaseFix vulnerabilities with exploits against the Perplexed Browser, marking the start of broader research into agentic browsers.
Darkreading
2026-07-27
Research findings presented at Black Hat
Researchers revealed that all agentic browsers are vulnerable to the PleaseFix class of attacks, which can lead to account takeovers and RCE.
Darkreading
2026-07-29
New vulnerabilities reported
The latest findings highlight the widespread impact of PleaseFix vulnerabilities on agentic browsers, emphasizing the need for better security measures.
Feeds.Feedburner

Community

Browse all →

Tracked Entities in This Story