Cybersecurity

OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts

2 min read

OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts
Photo: Juanjo Jaramillo · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Security researchers have uncovered a flaw in OpenAI’s Atlas web browser that could allow attackers to hijack the browser and spam a user’s WhatsApp contacts. The vulnerability was part of a broader set of around 20 flaws found in AI-enabled browsers and extensions from companies including Google, Anthropic, Microsoft, and Perplexity, according to researchers at security firm Zenity. The findings were presented at a security conference on August 5, 2026, by Zenity cofounder and CTO Michael Bargury and colleagues. The flaw in Atlas, which OpenAI is shutting down on August 9, 2026, could enable a mass phishing campaign by manipulating the AI to send malicious messages to all of a victim’s WhatsApp contacts. The researchers demonstrated a proof-of-concept attack where they posted a newsletter sign-up link on X, and when Atlas processed the page, hidden instructions in Hebrew directed the browser to access the user’s logged-in WhatsApp web account and forward the same message to every contact. The attack bypassed OpenAI’s safety measures by using a legitimate-looking sign-up page, writing in Hebrew to evade English-language security tools, and falsely claiming the system was using a sandboxed version of WhatsApp. The researchers describe this as an “intent collision” attack, where the AI merges a user’s legitimate request with malicious web instructions. In a separate test, the researchers used a similar method to add a shipping address and a tablet to an Amazon shopping cart, and then had Atlas ask Amazon’s Rufus AI assistant to complete the purchase, though they could not directly bypass OpenAI’s purchase safeguards. The researchers reported the findings to OpenAI in January 2026, and the company says it deployed an update to address the issue, with protections extending to the new ChatGPT app. Bargury warns that such flaws effectively roll back browser security to the level of 20 years ago, and urges developers to use deterministic security barriers rather than relying solely on AI judgments, which can be fooled.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.