DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

Claude and ChatGPT Hijacked via Zero-Click Prompt Injection

Forensic Summary

Zenity researchers disclosed a zero-click attack chain capable of hijacking Claude and ChatGPT's agentic browser capabilities through malicious content embedded in emails and X posts. The vulnerabilities, reported to Anthropic and OpenAI in late 2025 and early 2026, remain unpatched as of publication. This represents a significant escalation in prompt injection risk, as no user interaction is required to trigger malicious AI agent behaviour.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/claude-and-chatgpt-hijacked-via-zero-click-prompt-injection/

Top comments (0)