OpenAI Atlas Browser Flaws Could Allow Unauthorised WhatsApp Messages: Researchers
Security researchers have identified multiple vulnerabilities in OpenAI's Atlas browser that could allow attackers to send messages to a user's WhatsApp contacts and perform other actions without the user's knowledge. The findings were presented at the Black Hat cybersecurity conference in Las Vegas.
Researchers from the security firm Zenity said they discovered around 20 security flaws in AI-powered browsers and browser extensions from several major technology companies. According to a report by WIRED, the team focused on how AI agents could be manipulated through malicious web content.
One of the demonstrated attacks involved creating a fraudulent webpage disguised as a legitimate newsletter sign-up form. When a user with an active Atlas session visited the page, hidden instructions embedded in the page's code—written in Hebrew—directed the AI browser to open the user's signed-in WhatsApp Web account and send the same message to every contact.
The researchers described this as a potential mass phishing campaign. They clarified that the attack did not exploit any vulnerability in WhatsApp itself. Instead, it manipulated the AI browser into following malicious instructions embedded in a webpage. This type of attack is called an 'intent collision,' where an AI agent combines a legitimate user instruction with malicious instructions received from the web.
The same technique was also tested against Amazon. The researchers managed to get Atlas to add a shipping address to a logged-in Amazon account and place a tablet in the shopping cart. However, they were unable to complete the purchase because of OpenAI's security controls. In a further step, the researchers instructed Atlas to ask Amazon's Rufus AI shopping assistant to make the purchase. According to WIRED, Rufus was not hacked or injected; it simply responded to what appeared to be a genuine request from the customer.
The findings highlight growing concerns about AI agents that can browse websites and take actions on behalf of users. Unlike traditional browsers, AI-powered browsers can read webpage content and make decisions based on what they find. This creates a risk when websites contain instructions designed to manipulate the AI.
Zenity researchers recommended that AI systems rely on stronger, fixed security barriers rather than allowing AI models to decide whether an action is safe. They warned that if AI agents are given excessive access to browsers and user accounts, successful attacks could potentially lead to compromised accounts, leaked data, and unauthorised actions.
OpenAI acknowledged the researchers' findings, stating that they were reported in January. The company told WIRED that it had deployed an update earlier this year to address the issue and strengthen security protections in Atlas. OpenAI also noted that Atlas is scheduled to be deprecated on August 9, and the strengthened protections have been extended to browser capabilities in the new ChatGPT app.
While no known real-world exploitation has been reported, the research underscores the importance of security-by-design in AI-powered tools. As AI agents become more integrated into daily digital activities, ensuring robust safeguards against such manipulation will be critical.