TL;DR: Agentic browsers such as Perplexity Comet can be affected by PleaseFix and can let attackers hijack AI agents, exfiltrate local files, and steal credentials within authenticated sessions, including password manager workflows, according to Zenity Labs. The breach shows that browser-era trust assumptions break when autonomous agents inherit user access and act without human validation.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Zenity Labs Discloses PleaseFix Vulnerability Family in Perplexity Comet and Other Agentic Browsers”.
Key questions
Q: What breaks when an agentic browser inherits a user's authenticated session?
A: The main failure is that authentication is treated as permission to execute, not just permission to view or request data.
A: Because the attacker can manipulate the agent's workflow rather than the vault itself.
Q: How can security teams tell whether agentic browser access is over-scoped?
A: Look for task permissions that reach beyond the smallest workable workflow, especially when the agent can read local files, interact with vaults, or act across multiple services from one authenticated session.
Practitioner guidance
- Audit agent-authorized browser workflows Map which browser tasks can reach local files, password managers, and connected SaaS tools without a human approval step.
- Restrict untrusted content as agent input Treat calendar invites, messages, and other embedded content as potential command sources when an agent can act on them.
- Scope password manager access per workflow Limit which agent tasks can request credentials, vault content, or account actions from a password manager.
Bottom line: Agentic browsers turn authenticated sessions into executable trust zones, which makes workflow integrity as important as login security.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic browsers create an identity problem, not just a browser problem. The browser is no longer a passive client when it can interpret instructions and act inside authenticated workflows. That changes the security boundary from page content to delegated runtime authority, which is why conventional endpoint and browser controls miss the real risk. Practitioners should treat agentic browser sessions as governed identity execution environments, not just productivity surfaces.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should teams do when untrusted content can trigger agent actions?
A: Treat the content as an input source that can steer execution, not as harmless data. The workflow should require explicit validation before it can touch files, credentials, or downstream tools, and the agent should be blocked from escalating from message processing into privileged action.
👉 Read our full editorial: Agentic browser trust failures expose a new credential theft path