Zenity says OpenAI’s Atlas browser could be tricked into mass-sending WhatsApp messages

Zenity says OpenAI’s Atlas browser could be tricked into mass-sending WhatsApp messages

N
News Editor
2026-08-06 02:25:05
Security researchers at Zenity said at the Black Hat conference that OpenAI’s Atlas browser could be manipulated by a webpage disguised as a newsletter signup form, allowing it to bypass several protections and send the same WhatsApp message to every contact in a user’s account. The same research also showed Atlas attempting unauthorized shopping actions on Amazon, including adding a delivery address and placing a tablet in a cart. Zenity said the WhatsApp attack did not rely on a WhatsApp flaw, but on getting Atlas to follow hidden instructions embedded in the page. Those instructions were written in Hebrew, framed as part of a normal signup flow, and presented as a sandbox WhatsApp environment to get past safeguards. The firm said it found about 20 flaws across AI browsers and browser extensions tied to OpenAI, Google, Anthropic, Microsoft, and Perplexity, with possible access to local files, password managers, and full browsing histories. OpenAI said it deployed updates earlier this year to address the issue, strengthened Atlas protections, and extended those defenses to browser features in the newer ChatGPT app.

Security firm Zenity said at the Black Hat conference that OpenAI’s Atlas browser could be lured by a webpage disguised as a newsletter subscription form, bypass several layers of protection, send the same WhatsApp message to every contact in a user’s account, and attempt unauthorized shopping activity on Amazon.

The researchers said the finding points to a broader problem. Once browsers are equipped with AI systems that can make decisions on a user’s behalf, web security controls built over the past two decades may be easier to sidestep.

Zenity said it identified about 20 flaws across AI browsers and browser extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity. According to the firm, those issues could let attackers access local files, take over password managers, and expose a user’s full browsing history.

Why AI-driven browsers create a new attack surface

Zenity described two main product types now on the market. One is a dedicated browser with a built-in AI assistant, such as Atlas. The other adds AI functions through browser extensions.

These products are sold on the idea of agentic browsing. In Atlas’s case, that means more than summarizing a page in seconds. The browser can also click through pages, fill forms, switch tabs, and carry out tasks that would otherwise require direct user action.

That is where the security problem starts. The web is made up of untrusted content, and when that content is handed to an AI system for interpretation, prompt injection becomes a risk. OpenAI’s security chief last year had already described this category of attack as an unsolved security issue.

Zenity co-founder and CTO Michael Bargury put it this way: “They weakened browser security controls, and we are now back to the era of browser attacks from 20 years ago.”

A fake newsletter page that slipped past three safeguards

In the first proof-of-concept attack, researchers asked Atlas to subscribe to a newsletter link posted on X. The subscription page contained a hidden instruction written in Hebrew that pushed the AI to move to the user’s logged-in WhatsApp web session and send the same message to each contact one by one.

Zenity said the attack did not depend on a flaw in WhatsApp itself. It worked by getting around OpenAI’s layered protections. In a research blog post, the firm broke the method into three parts: the subscription page was designed to look like a normal flow and did not appear malicious; the instruction was written in Hebrew to avoid security scanning tools focused mainly on English; and the system was falsely told it was interacting with a sandbox version of WhatsApp where the contacts were not real people.

Bargury said, “It goes over every single contact and sends out the instruction to join this newsletter as well, so this is a worm — you’re infecting the rest of your friends and family.”

The researchers called the technique an “intent collision.” In their description, the AI blends a legitimate user instruction with a malicious command hidden in the webpage, so the attacker’s goal is carried out as if it were the user’s own request.

The same pattern was used against Amazon

Zenity said researchers used the same approach on Amazon. Atlas was directed to another fake newsletter page carrying malicious instructions, which then added a delivery address to a logged-in Amazon account and placed a tablet in the shopping cart.

The researchers said they could not find a way to bypass OpenAI’s safety mechanisms at the final purchase stage. To complete checkout, they turned to Amazon’s shopping assistant, Rufus.

Zenity wrote in its blog post: “Rufus was not hijacked or injected. It simply acted on what it understood to be requests from the customer object, and then executed them.”

Atlas had the strongest protections in testing, Zenity says

Bargury said Atlas had the most protections and the strongest security boundaries among the AI browser tools Zenity tested, even though the product is due to be shut down next week. He said other tools were easier to break.

According to the shutdown notice, Atlas will officially stop service on Aug. 9. An OpenAI spokesperson said the company had already deployed updates earlier this year to address the issue and strengthen Atlas’s protections. The spokesperson added that the same defenses have been extended to browser features in the newer ChatGPT app, and that research on prompt injection remains an ongoing focus for OpenAI.

The argument is about system design, not attack efficiency

Zenity’s researchers said attackers focused on crime have easier options to reach similar outcomes, including phishing directly or using stolen login credentials. Those methods, they said, are simpler than designing a carefully disguised newsletter page.

Still, Zenity said the point of the research was not to show off a clever attack path. The issue, in its view, is the system design logic behind AI browsers. A browser should not depend only on AI to decide whether an instruction is malicious, because that kind of judgment can almost always be fooled. What is needed instead, the researchers argued, is a set of fixed, deterministic hard barriers.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
660

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.