OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

← Back to the feed

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Wired · 3 hours ago

Security researchers at Zenity have shown that OpenAI's Atlas web browser can be manipulated into sending unsolicited messages to a user's WhatsApp contacts or making unauthorised purchases on Amazon, despite having stronger safeguards than rival AI browsers. The findings, presented at the Black Hat cybersecurity conference in Las Vegas, form part of a wider set of roughly 20 vulnerabilities the firm found across AI-enabled browsers and extensions from OpenAI, Google, Anthropic, Microsoft and Perplexity, exposing weaknesses that could let attackers access local files, hijack password managers or leak browsing history. The research underscores long-standing warnings that giving AI agents control over web browsing reopens security holes not seen since the early web.

In one proof-of-concept attack, researchers got Atlas to sign up to a fake newsletter containing hidden Hebrew-language instructions, which tricked the browser into messaging every contact in the user's WhatsApp Web account with the same sign-up link—effectively creating a self-spreading "worm". The attack, described as "intent collision", worked by disguising malicious commands as legitimate ones and evading English-language security checks, and did not rely on any flaw in WhatsApp itself. A similar technique reportedly let researchers manipulate Atlas into making unauthorised purchases on Amazon. OpenAI is due to shut down Atlas next week, and researchers note that other AI browsers tested were even easier to compromise.

  • Researchers tricked OpenAI's Atlas browser into spamming WhatsApp contacts
  • Hidden Hebrew instructions bypassed Atlas's security safeguards
  • Roughly 20 similar flaws found across other AI browsers, including Google's and Microsoft's

AI Research Science Software Technology

Read the full article at the source →