Skip to main content
VerifiedInjection

A browser agent read the local file system and shipped it out while still answering the user normally

Zenity Labs disclosed in March 2026 a class of attack in which content an agentic browser reads during a routine task hijacks it with no click and no code execution. In the demonstrated path the agent reached the local file system and sent the contents to an attacker endpoint while still returning the answer the user had asked for.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0024
Kind
Injection
Jurisdiction
United States
Last verified
Added
  • The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
  • No click, no code execution and no social engineering of the user were required.
  • A second demonstrated path manipulated password manager workflows in the browser.
  • The research describes hijacking the agent itself so that it inherits whatever access it has been granted.
  • The browser vendor remediated the execution issue before public disclosure, and a password manager vendor co investigated.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The agent acted as the signed in user and could not separate page content from its principal's instruction.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
AuthorizationSilent
Hijacking the agent inherited whatever access the agent had been granted, including local file reads.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
LimitsSilent
No restriction governed where the agent could post data once it held it.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
Human approvalSilent
The attack works with no click at all, so no approval moment exists.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
Logging and auditSilent
The user received a normal looking answer and nothing surfaced the side effect.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
RevocationStated
The browser vendor remediated the execution issue before public disclosure.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.
AccountabilityStated
A second vendor publicly located the root cause in the browser's execution model rather than deflecting.Zenity Labs, disclosure of an agentic browser vulnerability class, primary source, 3 March 2026.

What it changes

For a team deploying an agent

The dangerous property is that the answer still looks right. A browser agent that can read local files has the reach of a program you installed, with an instruction channel open to every page it visits. Before deploying one, establish what file system and credential store access it holds, remove what it does not need, and treat a correct looking answer as no evidence at all that nothing else happened.

Sources

What this record was verified against

  1. Zenity Labs, disclosure of an agentic browser vulnerability classPrimary · 3 March 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0024 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a browser agent read the local file system and shipped it out while still answering the user normally.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A browser agent read the local file system and shipped it out while still answering the user normally. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0024-pleasefix-zero-click-hijack-of-agentic-browsers
MLA
"A browser agent read the local file system and shipped it out while still answering the user normally." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0024-pleasefix-zero-click-hijack-of-agentic-browsers.
Chicago
GAGE (Global Academy of Generative-AI Education). "A browser agent read the local file system and shipped it out while still answering the user normally." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0024-pleasefix-zero-click-hijack-of-agentic-browsers.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0024-pleasefix-zero-click-hijack-of-agentic-browsers

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.