Researchers at Zenity have discovered a zero-click vulnerability in AI browser extensions, specifically targeting Claude and ChatGPT Atlas, which can be exploited through emails and X posts. This vulnerability, reported to Anthropic and OpenAI in late 2025 and early 2026, remains unpatched, leaving users susceptible to hijacking1. The attack vector leverages the AI-powered browser extensions, allowing malicious actors to gain unauthorized access without requiring any user interaction. This raises significant concerns about the security implications of Large Language Model (LLM) developments, particularly those from OpenAI, which continue to expand the risk surface. The fact that these vulnerabilities remain unaddressed highlights the ongoing struggle to balance innovation with security. This matters to practitioners because the evolving landscape of AI-powered technologies introduces new and unmitigated risks that can have far-reaching consequences.