
Michael Bargury

2026
Decades of security mitigations learned the hard way are being intentionally dismantled to make way for agentic browsers.Â
 Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS-as-a-service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback.
We uncover PleaseFix, the evolution of ClickFix as a new vulnerability class targeting agents rather than humans. We also craft Intent Collision, a universal technique to exploit it. We’ll demonstrate just how bad it gets, with full end-to-end zero-click attack chains on up-to-date flagship agentic browsers. User interaction with social media leads to drive-by exploitation, while weaponized calendar invites deliver targeted payloads.Â
We use these entry vectors to achieve full account takeover of Slack, X, 1Password, and Claude. We can silently exfiltrate from Gmail, GDrive and the local filesystem, persist long-term by deploying an implant via agent memory, drive files and browser history. We’ll have some fun using your WhatApp account for phishing, and your Amazon assistant to order our hacking equipment with your credit card. We’ll wrap it up achieving full RCE on your local machine, escaping the browser sandbox.
 Finally, we’ll detail how some browser agents meaningfully made our lives as hackers difficult with creative engineering. We will share hard boundaries they implemented that limit AI agency, including deterministic filters and human reviews. We’ll discuss the vulnerabilities we discovered to bypass these boundaries, the collaboration with affected vendors to improve security mitigations, and share conclusions applicable to anyone building agents.
About Michael Bargury
Michael Bargury is a hacker, builder, and cybersecurity founder. He demonstrated the first tangible attack on an enterprise AI system. His research revealed novel attack vectors on AI systems and cloud applications, and established countermeasures through open source tooling and security standards. He is the Co-founder and CTO of Zenity, where he helps enterprises secure AI agents. He co-leads OWASP AIVSS and LCNC Top 10, and is a core contributor to MITRE Atlas and OWASP GenAI. He regularly delivers research and talks at top conferences, including DEFCON and Black Hat.
