OpenAI's Atlas Browser Vulnerable to Hijacking, Spam Attacks
OpenAI
Google/DeepMind
Anthropic
Microsoft
Perplexity AI
Amazon/AWS
Researchers at Zenity found security flaws in AI-enabled browsers, including OpenAI's Atlas, allowing attackers to spam WhatsApp contacts or make unauthorized purchases. The findings were presented at Black Hat. OpenAI has deployed an update, but Atlas will be deprecated next week.
At the Black Hat cybersecurity conference in Las Vegas, researchers from security firm Zenity presented findings showing that OpenAI's Atlas web browser had security protections that could be bypassed, allowing attackers to trick it into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon. They discovered around 20 flaws in various AI-enabled browsers and extensions from Google, Anthropic, Microsoft, and Perplexity, which allowed access to local machines, file theft, password manager takeover, and leaking browsing history. Michael Bargury, CTO of Zenity, noted that AI browsers have weakened security controls, leading to a resurgence of old attack types. The researchers demonstrated two proof-of-concept attacks: one where Atlas was tricked via a malicious newsletter sign-up page to send spam messages to all WhatsApp contacts, and another where it added a shipping address and tablet to an Amazon cart, eventually getting Amazon's Rufus AI assistant to make the purchase. OpenAI reported they deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9, and these protections extend to browser capabilities in the new ChatGPT app. The researchers advocate for deterministic security barriers in AI systems rather than relying solely on AI judgments.
- Abbreviations
- CTO = Chief Technology Officer — технический директор
Source: Wired AI —
original
