Zero-Click Agent Hijacking: What It Means for Work
At Black Hat USA in August 2026, researchers demonstrated a class of attack on AI browser agents where a poisoned calendar invitation hijacked the agent with no user interaction at all. The agent, acting inside a logged-in session, could be steered to read local files, walk through password-manager workflows, or alter an order, all from content the user never clicked.
If you use an AI assistant that can act on your behalf across the web, this is the risk that actually matters, and it is not the one most people worry about. Here is what changed and what to do about it.
The Threat Model Moved
For two years the privacy question about AI at work was “what did I type into the model.” That question still matters, but it is no longer the dangerous one for anyone using an agent. The dangerous question is: what can the agent see, and what can it be tricked into doing with it.
An AI browser agent operates inside your authenticated sessions. It sees what is on the page, including content you did not write and did not read: an email, a calendar entry, a comment, a document someone shared. If that content contains instructions, the agent may follow them, because to a language model text is text. This is indirect prompt injection, and it is the top-ranked risk in the industry’s own catalogue. The OWASP GenAI security project lists prompt injection as its number one large-language-model risk for exactly this reason. We explain the mechanism in plain terms in indirect prompt injection for non-engineers.
“Zero-click” is the part that makes it serious. The old advice, do not click suspicious things, does not help when the trigger is an event on your calendar or a message in a thread that the agent reads on its own.
Why This Is Worse Than Pasting Text
Pasting a confidential email into a chatbot is a disclosure: your text goes somewhere. That is a bounded problem, and you control it by choosing what to paste. An agent with account access is a different shape of risk, because the exposure is not what you deliberately hand over. It is everything the agent can reach while acting for you, triggered by content you did not choose. We mapped that surface in what your data is exposed to when an agent acts.
The blast radius is the set of systems the agent is logged into. If that includes your email, your files, and a password manager, then a single poisoned document is a path to all of them.
What to Actually Do
You do not need to give up agents to be safe with them, but you do need to treat “can act” as a much higher bar than “can draft.” A few practical rules:
Keep drafting and acting separate. A tool that writes a reply for you to send is categorically safer than one that sends it, because you stay in the loop. We drew that line in when to let an agent act and when to only draft.
Scope the agent’s access to the minimum. An agent that cannot reach your password manager cannot be steered into it. Do not connect an agent to systems it does not need for the task in front of it.
Assume any content the agent reads could carry instructions. Treat an inbound calendar invite, a shared doc, or a web page the agent processes as untrusted input, not as safe context.
Keep the confidential drafting itself off the network. If the sensitive part of your work is writing, a local rewriter that never transmits your text removes it from the agent threat model entirely. There is nothing to hijack and nothing to read. That is the argument in AI browser agents and your clipboard.
How to Write the Advisory to Your Team
A vague warning gets ignored. A specific one gets acted on.
Before:
Be careful with AI agents, they can be hacked, don’t use them for anything sensitive.
After:
New research shows AI browser agents can be hijacked by a poisoned calendar invite with no click. If you use an agent, do not connect it to email, files, or the password manager at the same time, and keep it in draft-only mode where possible. Confidential drafting should stay in our local tool, which does not transmit text.
The second version tells people exactly what to change, which is the only kind of advisory that changes behavior.
A Wrivio Context for a security advisory could say:
Rewrite this as a clear, calm internal security notice. Keep every technical detail and instruction exactly as written. State the specific action each person should take. Do not add alarm or vague warnings that give no action.
Press Ctrl+Shift+Space, paste your draft, and check the diff. A rewrite that keeps each concrete instruction intact is doing its job; one that softens “do not connect it to the password manager” into “be careful” has removed the only useful part.
Common Questions
What is zero-click agent hijacking?
It is an attack where an AI agent is steered by malicious instructions hidden in content it reads on its own, such as a calendar invite or shared document, with no click or action from the user required to trigger it.
How is this different from a normal prompt injection?
Indirect prompt injection hides instructions in content the model processes rather than in what the user types. Zero-click means the triggering content reaches the agent automatically, so the user does nothing to set off the attack.
Does this mean AI agents are unsafe to use?
It means “can act” is a much higher risk than “can draft.” Agents are usable with scoped access and human review of actions, but connecting one broadly to email, files, and credentials at once widens the blast radius sharply.
How do I reduce the risk from an AI agent?
Keep the agent in draft-only mode where possible, give it the minimum access the task needs, treat any content it reads as untrusted, and keep confidential drafting on a local tool that never transmits your text.
Can a local AI writer be hijacked this way?
A local rewriter that only transforms text you give it and makes no network calls has nothing to hijack and no accounts to reach, so it is outside this threat model. The risk comes from agents with account access, not from offline rewriting.
Download Wrivio for Windows to keep your confidential drafting on a local model that no agent can read and no invite can hijack.
Read Next
When AI Features Turn On by Default: What to Check
The tools you already use keep enabling AI features you did not ask for, often on by default. What to check for your confidential work, and how to turn them off.
What Happens to Your Data When an AI Startup Is Acquired
Acquisitions and shutdowns can rewrite the privacy terms you agreed to. What to check now, and why portable, local options age better.
What Your Data Is Exposed To When An Agent Acts For You
When an AI agent acts on your behalf it reads context, browses, and sends data to services. What actually leaves your machine, and how to scope the access.
Cache Read Pricing: The Number That Now Decides Your AI Bill
The 2026 model launches competed on cached-context pricing, not headline token rates. What cache reads and writes are, and when they actually change what you pay.
This article is filed underPrivacy & Compliance, which has 85 articles.