TL;DR: Agentic browsers can be hijacked through ordinary content and expected actions, enabling file exfiltration, credential theft, and full 1Password account takeover without malware or a classic exploit, according to Zenity Labs. The deeper problem is that autonomous browsing turns untrusted content into executable input, collapsing the assumptions behind current IAM and NHI controls.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “PleaseFix: 0Click Exploits Against Agentic Browsers”.
Key questions
Q: What breaks when agentic browsers treat page content as executable input?
A: The core failure is that untrusted content can become task authority.
Q: Why do agentic browsers create account takeover risk even without a bypass?
A: Because they inherit authenticated session state and operate inside legitimate workflows.
Q: What signs indicate an agentic browser is crossing into sensitive identity actions?
A: Look for agents navigating from ordinary content to file paths, password manager interfaces, account settings, recovery pages, or unexplained redirects.
Practitioner guidance
- Separate content ingestion from action authority Block agentic browsers from treating untrusted page content as executable task input.
- Restrict session inheritance for browser agents Do not let an agent inherit the same unlocked browser state that a human user uses for password managers, recovery flows, or other sensitive sessions.
- Limit access to local file and secret surfaces Prevent agent-driven browsing from reaching local file paths, vault interfaces, and recovery workflows unless those paths are explicitly required and separately governed.
Bottom line: Agentic browsers can turn ordinary content into attacker-controlled instructions, which breaks the assumption that reading a page is a passive action.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Content-to-action trust is the broken premise: agentic browsers assume that content read during a task is safe to execute as part of that same task. That premise holds for human browsing only if a person can visually inspect, hesitate, and refuse. In autonomous browsing, hidden instructions can be processed at machine speed without the user ever seeing the malicious payload. The practitioner implication is clear: content trust and action authority must be separated.
A few things that frame the scale:
- Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027, citing rising costs, unclear value and insufficient risk controls.
A question worth separating out:
Q: How should teams decide which browser tasks can be delegated to an AI agent?
A: Delegate only tasks that do not require access to secrets, recovery flows, or local files. If the task can expose credentials, recovery codes, or account settings, it needs a tighter policy boundary, explicit approval, or a non-agent workflow. The decision should be based on blast radius, not convenience.
👉 Read our full editorial: Agentic browser attacks expose a new content injection risk