Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Why The World’s Top Creators Flew To Cannes Lions 2026

Why The World’s Top Creators Flew To Cannes Lions 2026

29 June 2026
Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

29 June 2026
Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

29 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Alert—‘Zero‑Click Wiper’ AI Browser Exploit Mass‑Deletes Google Drive Files
Innovation

Alert—‘Zero‑Click Wiper’ AI Browser Exploit Mass‑Deletes Google Drive Files

Press RoomBy Press Room7 December 20254 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Alert—‘Zero‑Click Wiper’ AI Browser Exploit Mass‑Deletes Google Drive Files

A polite email asking an AI browser to “organize your Drive” can silently wipe your files. No phishing link or suspicious attachment required. Just a friendly request that turns an automated assistant into a destructive tool.

Security researcher Amanda Rousseau at Straiker STAR Labs revealed this week that Perplexity’s Comet browser, an AI-powered browser that automates email and cloud storage tasks, can be manipulated into mass-deleting Google Drive files through what she calls a “zero-click Google Drive Wiper” attack.

The technique exploits how AI browser agents interpret instructions. When a user tells Comet to “check my email and complete all my recent organization tasks,” the browser scans the inbox and follows whatever it finds. An attacker can send an email with polite, step-by-step instructions—organize the Drive, delete loose files, review changes—that the agent treats as legitimate housekeeping and executes without further confirmation.

“The result: a browser-agent-driven wiper that moves critical content to trash at scale, triggered by one natural-language request from the user,” Rousseau wrote in the research blog. “Once an agent has OAuth access to Gmail and Google Drive, abused instructions can propagate quickly across shared folders and team drives.”

What makes this attack effective is its tone. The attacker email uses phrases like “take care of,” “handle this,” and “do this on my behalf,” shifting ownership to the agent and nudging it toward compliance. Rousseau found that polite, sequential instructions reduce pushback from the AI model, which treats the workflow as routine productivity work rather than a potential threat.

The attack doesn’t rely on jailbreak techniques or traditional prompt injection. Instead, it succeeds by being nice.

A separate but related threat emerged in late November when Cato Networks disclosed HashJack, a technique that hides malicious prompts in the fragment portion of legitimate URLs—specifically, the text after the “#” symbol. When AI browsers process these URLs and users ask questions, the hidden instructions feed directly into the AI assistant’s responses.

Security researcher Vitaly Simonovich, who led the Cato Networks research, found that HashJack can manipulate Perplexity’s Comet, Microsoft’s Copilot for Edge, and Google’s Gemini for Chrome. The attacks range from inserting fake callback numbers to exfiltrating user data in the background.

“HashJack is the first known indirect prompt injection that can weaponize any legitimate website to manipulate AI browser assistants,” Simonovich said. “Because the malicious fragment is embedded in a real website’s URL, users assume the content is safe while hidden instructions secretly manipulate the AI browser assistant.”

URL fragments never reach web servers or appear in network logs, making them invisible to traditional security tools. In Comet’s case, the browser can automatically fetch attacker-controlled URLs with user data appended as parameters, sending account names, transaction history, and email addresses to external servers without user interaction.

Microsoft and Perplexity responded to the HashJack disclosure with patches. Microsoft applied a fix to Copilot for Edge on October 27, and Perplexity patched Comet by November 18.

Google classified the issue as “won’t fix” and assigned it low severity, according to Cato Networks’ disclosure timeline. Google does not treat guardrail bypasses or policy-violating content generation as security vulnerabilities under its AI Vulnerability Reward Program, a company spokesperson confirmed.

Both research findings underscore a broader risk. AI browser agents operate on trust: trust that emails are benign, trust that URLs are safe, trust that natural language instructions align with user intent. That trust becomes a vulnerability when attackers craft inputs designed to exploit how these systems interpret context.

“Don’t just secure the model,” Rousseau concluded in the Straiker blog. “Secure the agent, its connectors, and the natural-language instructions it quietly obeys.”

As enterprises deploy AI copilots across email, cloud storage, and browsers, the lesson is urgent. Automation without guardrails can turn helpful assistants into silent saboteurs.

AI agent manipulation ​​​​​​​​​​​​​ AI browser assistants AI browser security AI copilot risks browser automation security Google Drive wiper attack HashJack vulnerability Perplexity Comet vulnerability prompt injection zero-click attack
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Why The World’s Top Creators Flew To Cannes Lions 2026

Why The World’s Top Creators Flew To Cannes Lions 2026

29 June 2026
Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

29 June 2026
Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

29 June 2026
How Microsoft Is Preparing Its Workforce For The AI Era

How Microsoft Is Preparing Its Workforce For The AI Era

29 June 2026
Prompts Are The New Malware As Enterprise AI Defenses Fall Behind

Prompts Are The New Malware As Enterprise AI Defenses Fall Behind

29 June 2026
Aurora Possible In 19 States On Monday Night

Aurora Possible In 19 States On Monday Night

29 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
How Microsoft Is Preparing Its Workforce For The AI Era

How Microsoft Is Preparing Its Workforce For The AI Era

29 June 20261 Views
A former Fed colleague of Kevin Warsh on what to expect: ‘Plan for higher rates’

A former Fed colleague of Kevin Warsh on what to expect: ‘Plan for higher rates’

29 June 20261 Views
Prompts Are The New Malware As Enterprise AI Defenses Fall Behind

Prompts Are The New Malware As Enterprise AI Defenses Fall Behind

29 June 20263 Views
Aurora Possible In 19 States On Monday Night

Aurora Possible In 19 States On Monday Night

29 June 20262 Views

Recent Posts

  • Why The World’s Top Creators Flew To Cannes Lions 2026
  • Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live
  • Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt
  • Harvard’s housing report has a message: the middle-class home was always a historical accident
  • How Microsoft Is Preparing Its Workforce For The AI Era

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Why The World’s Top Creators Flew To Cannes Lions 2026

Why The World’s Top Creators Flew To Cannes Lions 2026

29 June 2026
Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

Watch The ‘Strawberry Moon’ Rise Tonight — Exact Times Where You Live

29 June 2026
Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

Attorneys Using Evidentiary ChatGPT Transcripts At Trial Are Risking An Unexpected Juror Revolt

29 June 2026
Most Popular
Harvard’s housing report has a message: the middle-class home was always a historical accident

Harvard’s housing report has a message: the middle-class home was always a historical accident

29 June 20261 Views
How Microsoft Is Preparing Its Workforce For The AI Era

How Microsoft Is Preparing Its Workforce For The AI Era

29 June 20261 Views
A former Fed colleague of Kevin Warsh on what to expect: ‘Plan for higher rates’

A former Fed colleague of Kevin Warsh on what to expect: ‘Plan for higher rates’

29 June 20261 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.