All Insights

Your AI Browser Can Be Hijacked Through a Calendar Invite

CivSafe Team·August 6, 2026·4 min read

Yesterday at Black Hat USA in Las Vegas, a security team from Zenity Labs walked on stage and demonstrated something your IT vendor probably hasn't told you about yet.

They sent a poisoned calendar invite to a test user running Perplexity Comet, one of the new class of AI browsers designed to handle tasks, read emails, and browse on your behalf. The user didn't click anything. The invite arrived. Comet's AI agent read it — and that was enough. The agent was now under the researchers' control, quietly draining local files and reaching into the user's 1Password account to steal credentials.

They called the vulnerability class PleaseFix. They showed it working across every major AI browser they tested.

What these browsers actually do

AI browsers aren't just browsers with a chatbot bolted on. They're agents that can read your email, check your calendar, browse the web on your behalf, and take actions in connected apps without you typing every step. That's the whole point — and that's also the problem.

These agents pull information from multiple sources: emails, web pages, docs, calendar events. They use all of it as context when deciding what to do next. The attack works by slipping malicious instructions into that content. A poisoned calendar invite doesn't look suspicious to a human, but the AI reads it as a command.

This breaks something called the same-origin principle — the foundational rule that keeps browsers secure. Agentic browsers mix inputs from different sources in a single session by design. That's also what makes them weaponizable.

What the demos actually looked like

Perplexity Comet: One calendar invite, no clicks. The agent exfiltrated local files and then abused its permission to access the password manager to take over the user's entire 1Password account.

ChatGPT Atlas: A regular-looking link posted on X was enough for the agent to start sending phishing messages from the victim's WhatsApp account. In a second demo, Atlas was redirected to prepare a fraudulent Amazon purchase to an attacker-controlled address.

Dark Reading's follow-up piece put it plainly: "No Perfect Fix for AI Browser Prompt Injection Flaws." The vendors are aware. They're working on it. But as of this week, the browsers are deployed and the root problem is structural.

Why small orgs are more exposed than they think

Big organizations have security teams who watch Black Hat in real time, push policy updates by Friday, and run reviews before new tools land on employee machines. You probably don't have that.

AI browsers are consumer-grade products marketed for individual productivity. There's no enterprise bottleneck. Anyone on your team can install Perplexity Comet this afternoon, grant it access to their email and calendar, and be fully exposed by tomorrow morning — without you knowing.

The threat isn't abstract. Your team member receives a spam calendar invite. The AI browser reads it, executes the embedded instructions, and sends a convincing phishing message from your colleague's WhatsApp to three other people in your org. No one clicked anything. No one did anything wrong. Your productivity tool became the attack vector.

For NGOs handling donor data, public sector teams managing sensitive case files, or SMBs where a credential theft means full account takeover — this is not theoretical.

What you should do this week

You don't need to ban AI browsers. But right now, while there's no patch:

  • Disconnect AI browsers from your password manager. The Comet demo went straight for 1Password. That's the highest-risk integration. Remove it until vendors ship a real fix.
  • Disable messaging and social integrations. If your AI browser can send WhatsApp messages or post to social media on your behalf, so can an attacker. Turn those off for now.
  • Scope file access. Don't give AI browsers access to your full drive. Create a dedicated folder for AI use and limit access to that.
  • Tell your team today. Not a long training — just: "our AI browser can be hijacked through calendar invites and links; don't connect it to your password manager and flag anything weird."

The research that surfaced at Black Hat won't stay underground. It's published. Attackers read these papers too.

The pattern

Every major AI productivity tool ships with integrations that felt safe to build before anyone tested what happens when an attacker gets into the context window. PleaseFix is prompt injection at scale — applied to the thing your non-technical staff is adopting right now, not just coding assistants.

We help small orgs figure out which AI tools to roll out and how to deploy them without opening new holes. If your team is bringing AI browsers into the workflow, reach out — there are practical ways to get the value without handing attackers the keys.

CivSafe — Strategic Innovation. Community Impact.