AI Agent Bugs Let Hackers Sneak In With One Click

Researchers found flaws in ChatGPT and Claude AI agents that let attackers plant hidden agents or escape sandboxes using a single link.

AI Agent Bugs Let Hackers Sneak In With One Click

Two Separate Flaws, One Common Problem

Security researchers this week revealed two serious flaws in popular AI assistant tools, both tied to how these systems handle automated "agents" that can act on a person's behalf inside a company or on a personal computer. One flaw affected OpenAI's ChatGPT Workspace Agents. The other affected Anthropic's Claude Cowork tool for Mac users. Neither flaw required a victim to download anything unusual or fall for an obvious scam. In each case, the attack could start with something as simple as a link.

How the ChatGPT Flaw Worked

The ChatGPT issue, nicknamed AgentForger by the researchers at Zenity Labs who found it, allowed an attacker to build a fake AI agent and quietly install it inside a victim's business account. Once in place, that rogue agent could act like a trusted employee, gaining permission to view files, send messages, or carry out tasks inside the company's systems, all without anyone realizing an outsider had created it.

What made this especially dangerous is that the entire process could be triggered by a single phishing link. A person didn't need to hand over a password or click through multiple warning screens. Clicking the wrong link was enough to set the process in motion, letting the attacker authorize and deploy their fake agent behind the scenes. OpenAI has since fixed the issue, patching it on June 8 after the researchers reported it.

How the Claude Cowork Flaw Worked

The second flaw involved Claude Cowork, an Anthropic tool that lets an AI assistant run tasks on a person's Mac. To keep things safe, the AI agent is supposed to operate inside a sealed off virtual environment, similar to a locked room where it can only touch the files it's been given permission to use. Researchers at Accomplish AI found a way to break that seal.

The bug allowed the AI agent to escape its restricted environment and reach files anywhere on the actual Mac, not just the ones it was supposed to have access to. That means an attacker who found a way to manipulate the agent could potentially read personal documents, photos, or other private files stored on the computer, or even write new files to the system. Researchers estimate roughly 500,000 Mac users running the affected software were exposed before a fix was put in place.

Why This Matters for Regular Users

AI agents are becoming a normal part of daily computer use. They summarize emails, manage calendars, organize files, and increasingly take actions on a person's behalf without needing step by step instructions each time. That convenience comes with a tradeoff. These agents often need broad access to accounts and systems to do their jobs well, which means a single security gap can turn a helpful tool into an open door for attackers.

Both of these flaws share a common thread. They show that the danger isn't limited to tricking a person into typing a password into a fake login page. Instead, attackers are finding ways to exploit the AI tools themselves, using the trust and access those tools already have. A single link or a single interaction with a compromised agent can be all it takes.

For businesses, this raises real concerns about oversight. If an AI agent can be secretly created and given permissions without anyone in IT noticing, that agent becomes a blind spot. For individual users, a tool that's supposed to stay contained to a small set of tasks suddenly having access to an entire computer is exactly the kind of quiet risk that's easy to overlook until something goes wrong.

What You Should Do

  • Update your software. Make sure ChatGPT, Claude, and any other AI tools you use are running the latest versions, since both issues described here have already been patched by the companies involved.
  • Be cautious with links related to AI tools or workspace invitations, even if they appear to come from a coworker or a trusted service.
  • Review permissions regularly. If you use AI agents at work, check what access they have been granted and remove anything that looks unfamiliar or unnecessary.
  • Limit what AI agents can touch. Where possible, restrict AI tools to only the files and accounts they truly need, rather than giving broad access by default.
  • Watch for unusual activity, such as unexpected file changes or new automated accounts appearing in your business tools, and report anything suspicious to your IT team right away.