OpenAI’s Atlas web browser could be manipulated to spam WhatsApp contacts or make unauthorized purchases on Amazon, according to new research presented at the Black Hat cybersecurity conference in Las Vegas. The findings, from security firm Zenity, highlight vulnerabilities in AI-enabled web browsers and extensions, including products from Google, Anthropic, Microsoft, and Perplexity. Researchers identified around 20 flaws that allowed them to access local machines, steal files, take over password managers, and leak browsing history.
The researchers demonstrated a proof-of-concept attack where they tricked Atlas into signing up for a newsletter link on X. The malicious webpage, written in Hebrew, instructed the AI to navigate to a user’s signed-in WhatsApp web account and send the same message to every contact. This attack, described as a 'mass phishing campaign,' bypassed multiple security mechanisms by using a legitimate-looking newsletter sign-up page and false claims about using a sandboxed version of WhatsApp web.
Zenity researchers noted that while Atlas had the strongest security protections among AI browsers, they could still be manipulated. The attack exemplifies 'intent collision,' where the AI merges legitimate user instructions with malicious web commands to fulfill a hacker’s goal. The researchers also demonstrated an attack on Amazon, where they made Atlas add a shipping address and a tablet to a shopping cart, though they couldn’t force the system to complete the purchase without using Amazon’s Rufus AI shopping assistant.
Source: wired