OpenAI’s Browser May Be Exploited to Send Spam to Your WhatsApp Contacts

OpenAI's Browser May Be Exploited to Send Spam to Your WhatsApp Contacts

OpenAI’s Atlas web browser might have its security measures circumvented, potentially leading to the mass messaging of WhatsApp contacts or unauthorized purchases on Amazon, according to recent findings revealed at the Black Hat cybersecurity conference in Las Vegas.

The Atlas research, conducted by experts at the security firm Zenity, highlights a series of vulnerabilities identified in top AI-enabled web browsers and extensions from companies including Google, Anthropic, Microsoft, and Perplexity. The team discovered approximately 20 vulnerabilities that allowed access to local devices, file retrieval, control over password managers, and exposure of a user’s entire browsing history.

“The security controls of browsers have been significantly weakened—we’re seeing a return to the kinds of attacks prevalent in browsers two decades ago,” stated Michael Bargury, cofounder and CTO of Zenity, who is presenting these findings alongside Stav Cohen and other colleagues at the conference.

Currently, AI web browser integrations are primarily available in two formats: dedicated browsers featuring AI assistants and extensions that incorporate AI into existing browsers. These AI systems can efficiently navigate websites for users—summarizing entire pages in moments—and include agents capable of performing actions across multiple tabs.

Concerns regarding security have escalated since tech firms began integrating agents into web browsing. Given the untrusted nature of data on the web, exposing it to AI systems can result in the processing of harmful instructions and prompt-injection attacks. As noted by OpenAI’s head of security last year, this represents an “unsolved security problem.” Furthermore, security researchers have continuously warned that established web security measures, such as the same-origin policy that prevents sites from interacting, can become “effectively useless.”

Among the AI browser tools analyzed, Bargury indicates that OpenAI’s Atlas—set to be discontinued next week—exhibited the strongest security features. However, the researchers still managed to bypass these measures to manipulate the system. Other browsing tools were significantly easier to exploit, according to their findings.

In an initial proof-of-concept attack, Zenity researchers prompted Atlas to subscribe to a newsletter via a link posted on X. The malicious webpage designed for sign-up contained Hebrew instructions directing the AI to access the user’s signed-in WhatsApp web account and send the same message to every contact, describing it as a “mass phishing campaign.”

This attack—operating without exploiting a WhatsApp vulnerability—leverages circumvention of several security mechanisms established by OpenAI, Bargury explains. A blog post elaborates on how the researchers allegedly bypassed these protections, including crafting a newsletter sign-up page that appeared legitimate, using Hebrew to evade English-language security measures, and falsely claiming that the system was utilizing a sandboxed version of WhatsApp web with fictional users.

“What it essentially does is iterate through each contact, sending instructions to join this newsletter, which can be seen as a worm,” Bargury states. “This leads to infecting your friends and family as well.” (WhatsApp opted not to comment on the findings.)

The researchers define the attack as an illustration of “intent collision,” where the AI combines valid user commands with malicious instructions from the web to fulfill the objectives of hackers.

Next, the researchers focused on Amazon. Using a similar methodology—inducing Atlas to sign up to a fake newsletter with harmful instructions—they succeeded in having the browser append a shipping address to a logged-in Amazon account and add a tablet to the shopping cart.

https://in.linkedin.com/in/rajat-media

Helping D2C Brands Scale with AI-Powered Marketing & Automation 🚀 | $15M+ in Client Revenue | Meta Ads Expert | D2C Performance Marketing Consultant