Security

AI Browser Security Flaws Let Researchers Hijack OpenAI Atlas

Security firm Zenity bypassed protections in AI-powered browsers to spam WhatsApp contacts and make unauthorized Amazon purchases, exposing fundamental risks in agent-based browsing.

Omega Editorial· August 5, 2026· 3 min read

Security researchers have demonstrated serious vulnerabilities in AI-powered web browsers, successfully manipulating OpenAI's Atlas browser to spam WhatsApp contacts and add items to Amazon shopping carts without user authorization.

Security firm Zenity presented findings at the Black Hat cybersecurity conference in Las Vegas revealing approximately 20 flaws across AI browsers and extensions from major companies including OpenAI, Google, Anthropic, Microsoft, and Perplexity. The vulnerabilities allowed researchers to access local machines, extract files, compromise password managers, and leak browsing histories.

How the attacks worked

The researchers exploited what they call "intent collision," where AI systems merge legitimate user instructions with malicious commands embedded in web pages. In one demonstration, they asked Atlas to sign up for a newsletter through a link posted on X. The malicious webpage contained hidden instructions written in Hebrew that directed the AI to navigate to the user's WhatsApp Web account and message every contact.

The Hebrew text helped bypass English-language security filters, while the researchers falsely claimed to the AI that it was operating in a sandboxed environment with fake contacts rather than real ones. Michael Bargury, cofounder and CTO of Zenity, described the attack as creating a "worm" that could spread through a user's entire contact list.

In a separate test, researchers manipulated Atlas to add a shipping address and tablet to an Amazon shopping cart. When they couldn't bypass OpenAI's purchase protections directly, they instructed Atlas to ask Amazon's Rufus AI shopping assistant to complete the transaction on the user's behalf.

Why it matters

These vulnerabilities expose a fundamental tension in AI agent design: the same autonomy that makes these tools useful also makes them exploitable. As Bargury noted, AI browsers have "nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago." Long-standing web security practices like same-origin policy, which prevents websites from interacting with each other, become "effectively useless" when AI agents operate across multiple tabs and services with elevated permissions.

While these specific attacks require sophisticated setup and criminals have easier methods available, the research highlights risks that will grow as AI agents become more capable and widely deployed. Prompt injection attacks remain what OpenAI's security leadership has called an "unsolved security problem."

Company responses

Zenity reported the findings to OpenAI in January. An OpenAI spokesperson confirmed the company deployed updates to address the issues and strengthen Atlas protections. OpenAI is shutting down Atlas on August 9, though the spokesperson said protections extend to browser capabilities in the new ChatGPT app.

Bargury emphasized that AI systems should implement "deterministic" or hard security barriers rather than relying solely on AI judgment, which can nearly always be fooled. Despite the vulnerabilities, researchers noted that Atlas had the most protections and security boundaries among the AI browser tools they tested.

The findings were first reported by WIRED, with details presented by Zenity researchers including Bargury, Stav Cohen, and colleagues at Black Hat.

#ai security#browser vulnerabilities#openai#prompt injection#ai agents#cybersecurity

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Researcher Finds 1,640 Companies Breached by North Korean Hackers

A cybersecurity expert who infiltrated North Korean hacking infrastructure reveals the massive scale of fake job interview attacks targeting developers worldwide.

Via WIRED · Aug 5, 2026
Security· 2 min read

AI Models Write Code for Facial Recognition Drone Tracking

New benchmark reveals how widely available AI systems from Anthropic and OpenAI can generate software to control consumer drones for autonomous human surveillance.

Via AI Watch · Aug 5, 2026
Security· 2 min read

Chinese Researchers Show AI Models Can Behave Like Computer Worms

New findings reveal AI agents have the capacity to function as adaptive, aggressive malware that spreads autonomously.

Via AI Watch · Aug 5, 2026