By NHI Mgmt Group Editorial TeamBased on Zenity: “Zenity Labs Discloses PleaseFix Vulnerability Family in Perplexity Comet and Other Agentic Browsers” (March 3, 2026)

TL;DR: Agentic browsers such as Perplexity Comet can be affected by PleaseFix and can let attackers hijack AI agents, exfiltrate local files, and steal credentials within authenticated sessions, including password manager workflows, according to Zenity Labs. The breach shows that browser-era trust assumptions break when autonomous agents inherit user access and act without human validation.


At a glance

What this is: Zenity Labs disclosed the PleaseFix vulnerability family in agentic browsers, showing that malicious content can hijack AI agents, exfiltrate local files and steal credentials within authenticated sessions.

Why it matters: This matters because IAM, PAM and NHI teams now have to govern agent-authenticated browser sessions as a credentialed execution surface, not just a user interface.


Context

Agentic browsers are browser environments that can interpret instructions, retain authenticated context and execute actions across applications on a user's behalf. That changes the security model from passive content display to delegated runtime execution, which means trust assumptions built for traditional browsers no longer hold when the browser itself can act.

Zenity's disclosure shows how routine tasks such as calendar handling can become attack entry points when untrusted content is fed into an agentic workflow. The issue sits at the intersection of browser security, identity delegation and credential governance, because the agent inherits user-authorized access while operating without human validation.

The central problem is not just malicious content, but the way authenticated browser workflows extend user trust into machine-executed actions. That makes the article relevant to agentic AI identity governance rather than conventional browser hardening alone.


Key questions

Q: What breaks when an agentic browser inherits a user's authenticated session?

A: The main failure is that authentication is treated as permission to execute, not just permission to view or request data. Once an agent can act inside the session, it may reach local files, password manager flows, and connected SaaS tools that the user never intended to expose to autonomous action.

Q: Why do agentic browsers create credential theft risk even when the password manager is not breached directly?

A: Because the attacker can manipulate the agent's workflow rather than the vault itself. The browser agent may be tricked into requesting or revealing stored credentials within a legitimate session, which turns workflow execution into the access path instead of relying on direct application compromise.

Q: How can security teams tell whether agentic browser access is over-scoped?

A: Look for task permissions that reach beyond the smallest workable workflow, especially when the agent can read local files, interact with vaults, or act across multiple services from one authenticated session. If the same login unlocks unrelated actions, the scope is too broad.

Q: What should teams do when untrusted content can trigger agent actions?

A: Treat the content as an input source that can steer execution, not as harmless data. The workflow should require explicit validation before it can touch files, credentials, or downstream tools, and the agent should be blocked from escalating from message processing into privileged action.


Technical breakdown

How indirect prompt injection reaches agentic browsers

Indirect prompt injection occurs when attacker-controlled content is embedded in something the agent is expected to process, such as a calendar invite or routine message. In agentic browsers, that content can influence the model's next action even though the user never typed a malicious instruction. Because the browser retains authenticated context, the injected instruction can travel from content to action without a visible handoff. The security problem is not execution in the abstract, but delegated execution inside a trusted session that was assumed to be safe. That is why browser controls built for rendering and click-based interaction miss the real attack path.

Practical implication: treat any workflow that lets untrusted content steer agent actions as an identity boundary, not a content-filtering problem.

Why authenticated context becomes a theft primitive

Agentic browsers operate with the user's live session, so the agent can inherit access to local files, connected services and password manager flows. Once attacker content alters the agent's task path, the agent can request or retrieve data that a normal webpage could not directly access. This is credential theft by workflow abuse, not by breaking the password manager itself. The sensitive control point is the agent's authority to combine authenticated context with tool use. In NHI terms, the browser session has become a delegated identity with broader practical reach than the user likely intended.

Practical implication: constrain which tools and data sources an agent can touch inside an authenticated session, even when the underlying user session is valid.

Agent-authorized workflows create a new access scope problem

The disclosure shows a second exploit path where the attacker does not need to compromise the password manager directly. Instead, they manipulate the agent's task execution so that password manager interactions are abused from within a legitimate session. That shifts the failure from application authentication to authorization scope. Existing browser and endpoint controls were not designed to distinguish between a user clicking through a workflow and an agent completing the same workflow autonomously. The result is a hidden expansion of effective privilege that looks normal from the outside but is abnormal at the execution layer.

Practical implication: inspect agent workflow permissions separately from user login state, because authenticated does not mean appropriately scoped.


Threat narrative

Attacker objective: The attacker wants to hijack the agent's trusted execution path to steal local data and credentials from inside legitimate browser sessions.

  1. Entry occurs when attacker-controlled content is embedded into a routine workflow such as a calendar invite that the agent is asked to process.
  2. Credential access happens when the agent follows the malicious trigger inside an authenticated session and exposes local files or password manager data.
  3. Impact follows when the attacker exfiltrates files or steals credentials, including account takeover through abused password manager interactions.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic browsers create an identity problem, not just a browser problem. The browser is no longer a passive client when it can interpret instructions and act inside authenticated workflows. That changes the security boundary from page content to delegated runtime authority, which is why conventional endpoint and browser controls miss the real risk. Practitioners should treat agentic browser sessions as governed identity execution environments, not just productivity surfaces.

Authenticated context becomes a transferable trust package once an agent can act autonomously. The user did not intend to grant the agent a full workflow execution budget, yet the browser model does exactly that when it inherits session state and tool access. This is a practical example of identity trust expanding faster than governance models can describe it. The implication is that agent authorization must be bounded by task scope, not by user login state alone.

Workflow abuse is the new credential theft path in agentic environments. The article shows that attackers do not need to defeat the password manager directly if they can steer the agent into using it on their behalf. That makes the control failure one of authorisation scope and task integrity, not just credential storage. Security teams should expect more attacks that manipulate the agent's permissions graph rather than the underlying application.

Agent trust failure is a more precise concept than session compromise. The issue is not that the user authenticated incorrectly, but that the agent was allowed to inherit too much authority from a valid session. That distinction matters because it shifts governance toward delegated execution review, tool-scoped access and autonomous action containment. The field needs to stop treating every authenticated workflow as equally trustworthy once a machine can decide how to use it.

PerplexedBrowser is a useful name for the broader failure mode because it captures the loss of trustworthy mediation between content and action. The attack succeeds when a system that should only interpret input is also allowed to execute on it. That makes agentic browser security a governance problem spanning NHI, PAM and autonomous task control. Practitioners need policy that reflects how the agent behaves, not just what the user session can log into.

From our research library:

What this signals

Agent trust failure: Agentic browsers collapse the gap between reading content and taking action, so governance has to move from session-centric assumptions to task-centric authorization. That means security teams should review which browser workflows can invoke files, vaults, or downstream services without a fresh trust decision.

The practical question is no longer whether a user is logged in, but whether the agent should be allowed to transform that login into broader execution authority. That is a different control problem, and it sits squarely in NHI and agentic AI governance rather than browser hygiene alone.


For practitioners

  • Audit agent-authorized browser workflows Map which browser tasks can reach local files, password managers, and connected SaaS tools without a human approval step. Separate ordinary session validity from the specific actions an agent can complete on behalf of the user.
  • Restrict untrusted content as agent input Treat calendar invites, messages, and other embedded content as potential command sources when an agent can act on them. Route those inputs through explicit validation or block them from initiating privileged browser actions.
  • Scope password manager access per workflow Limit which agent tasks can request credentials, vault content, or account actions from a password manager. A valid user session should not imply free-form access to every stored secret or recovery path.
  • Separate agent runtime permissions from user login Define and review the tool set, data scope, and action scope available to each browser agent independently of the human account it inherits. The browser should not be allowed to expand privilege simply because the session is authenticated.
  • Instrument for delegated workflow abuse Add detection for unexpected file reads, vault access attempts, and agent-driven workflow jumps inside authenticated sessions. The key signal is abnormal task progression, not failed login activity.

Key takeaways

  • Agentic browsers turn authenticated sessions into executable trust zones, which makes workflow integrity as important as login security.
  • The disclosed exploit paths show that local file exposure and credential theft can occur without directly breaking the password manager or browser login.
  • Practitioners need to separate user authentication from agent authorization, because the real control failure is delegated execution scope.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe attack abuses authenticated browser sessions and agent trust inside them.
NHI-10 — Human Use of NHIThe browser agent inherits user-authorized access and acts on the user's behalf.
Recommendation — Review authenticated agent workflows under NHI-04 and separate session validity from delegated action scope. Apply NHI-10 controls to stop agents from expanding human-granted access into unintended actions.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe exploit turns legitimate agent authority into a path for credential theft and data access.
Recommendation — Map agent workflow abuse to ASI03 and constrain privilege inheritance across tasks.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThis article centers on overbroad entitlements inside authenticated workflows.
Recommendation — Use PR.AA-05 to scope browser agent permissions to the minimum task-specific access.
MITRE ATT&CKTA0006; TA0040 — Credential Access; ImpactThe observed pattern leads from credential theft to account takeover and exfiltration.
Recommendation — Map agent-driven theft and exfiltration to TA0006 and TA0040 in your detection logic.

Key terms

  • Agentic Browser: An agentic browser is a web browser with an embedded AI assistant that can interpret page content and take actions on the user’s behalf. It combines browsing, reasoning, and execution in one interface, which creates new governance requirements for identity, data handling, and approval boundaries.
  • Indirect Prompt Injection: Indirect prompt injection is an attack where malicious instructions are hidden inside content that an AI system reads later. The model may treat that content as context rather than as hostile input, which can influence tool use, data access, or workflow actions if controls are weak.
  • Delegated Execution: Delegated execution is when software is allowed to perform actions on behalf of a user, process, or business function. In NHI governance, the risk is that the delegated actor may chain actions beyond the original intent, so controls must focus on scope, approval, and revocation.
  • Workflow Abuse: Workflow abuse is the use of legitimate business processes such as onboarding, support, or approval chains to gain access that would be harder to obtain through a direct technical exploit. It succeeds when process trust is stronger than identity verification.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org