ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Artificial Intelligence

Zero-click takeover of Claude and ChatGPT Atlas via email and X posts

Source headline: Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Zenity researchers describe a zero-click compromise path that can hijack Claude and ChatGPT Atlas sessions. The technique relies on malicious email and links originating from X posts rather than user-initiated actions. Affected users may see their AI browser context manipulated to enable further unauthorized activity. The findings were shared with Anthropic and OpenAI in late 2025 and early 2026, but patch status appears unresolved. Until fixes land, organizations should tighten email and social-link filtering and review browser and AI workflow access controls.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#social-engineering #session-hijacking #ai-browsing #email-phishing #zero-click
Original reporting SecurityWeek Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Open original source