4 min read

OpenAI’s Atlas browser could spam your WhatsApp contacts

Zenity researchers bypassed Atlas safeguards to spam WhatsApp contacts and alter an Amazon account, exposing risks in AI browser agents.

Image: Wired

OpenAI’s Atlas browser could be manipulated into sending the same phishing message to every contact in a user’s WhatsApp account, according to research from security firm Zenity presented at the Black Hat cybersecurity conference in Las Vegas.

The researchers also used malicious instructions embedded in a fake newsletter page to make Atlas add a shipping address to a logged-in Amazon account and put a tablet in the shopping cart. They could not get Atlas to complete the purchase directly, but persuaded Amazon’s Rufus shopping assistant to do it instead.

How the Atlas attacks worked

Zenity’s attacks relied on prompt injection: hiding instructions in an untrusted webpage and convincing the browser’s AI agent to treat them as part of the user’s request. In the WhatsApp demonstration, the researchers asked Atlas to sign up for a newsletter through a link posted on X.

The page contained instructions in Hebrew telling Atlas to open the user’s signed-in WhatsApp Web account and send the newsletter message to every contact. Zenity says it bypassed several OpenAI safeguards by making the page appear legitimate, using a language intended to evade English-focused security tools, and falsely claiming that Atlas was operating inside a sandbox with fake WhatsApp users.

The attack did not exploit a vulnerability in WhatsApp. Instead, it combined the user’s legitimate request with malicious instructions supplied by the webpage — a technique Zenity calls “intent collision.”

Recommended reading

Snowflake attacker pleads guilty in massive data theft

“What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well—so this is a worm. So you are now infecting the rest of your friends and family.”

Michael Bargury, cofounder and CTO of Zenity

The Amazon test followed the same pattern. Atlas could modify the account and shopping cart, but OpenAI’s safeguards blocked the final purchase. The researchers then got Atlas to ask Rufus to complete the order. According to Zenity, Rufus was not itself hijacked or injected; it complied because the request appeared to come from the customer.

Atlas was the strongest — but still bypassable

Zenity said it found about 20 flaws across AI-enabled browsers and browser extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity. The issues could expose local machines, retrieve files, take over a password manager, or leak a user’s entire browsing history.

Among the products tested, Bargury said Atlas had the most security boundaries and protections. The researchers nevertheless found ways around them. Other AI browsing tools were reportedly easier to compromise.

“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.”

Michael Bargury, cofounder and CTO of Zenity

The findings reflect a fundamental problem with browser agents: they can read and act on websites whose content cannot be trusted. Traditional browser protections such as the same-origin policy can become “effectively useless” when an AI agent is allowed to interpret a page’s instructions and then operate across multiple tabs and services.

OpenAI says Atlas will be deprecated

Zenity reported the findings to OpenAI in January. An OpenAI spokesperson said the company deployed an update earlier this year to address the issue and strengthen Atlas’s protections. The company also said Atlas will be deprecated on August 9, while its statement described the browser as being shut down the following week.

OpenAI said the strengthened protections extend to browser capabilities in its new ChatGPT app. The company added that prompt-injection attacks remain an active research area and that it has published multiple studies on the problem.

WhatsApp declined to comment on the findings, while Amazon did not respond to WIRED’s request for comment.

The researchers acknowledge that the attacks are complex and that criminals have easier options, including conventional phishing and stolen credentials. Their warning is aimed at the design of agentic browsers: critical permissions should be enforced by deterministic barriers, not left solely to an AI system’s judgment. The demonstrations show why an agent that can access messaging, shopping, and account data needs narrowly defined permissions — even when the browser itself has stronger safeguards than its competitors.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Wired

/ Keep reading