OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts
Security researchers have uncovered a flaw in OpenAI’s Atlas web browser that could allow attackers to hijack the browser and spam a user’s WhatsApp contacts. The vulnerability was part of a broader set of around 20 flaws found in AI-enabled browsers and extensions from companies including Google, Anthropic, Microsoft, and Perplexity, according to researchers at security firm Zenity. The findings were presented at a security conference on August 5, 2026, by Zenity cofounder and CTO Michael Bargury and colleagues. The flaw in Atlas, which OpenAI is shutting down on August 9, 2026, could enable a mass phishing campaign by manipulating the AI to send malicious messages to all of a victim’s WhatsApp contacts. The researchers demonstrated a proof-of-concept attack where they posted a newsletter sign-up link on X, and when Atlas processed the page, hidden instructions in Hebrew directed the browser to access the user’s logged-in WhatsApp web account and forward the same message to every contact. The attack bypassed OpenAI’s safety measures by using a legitimate-looking sign-up page, writing in Hebrew to evade English-language security tools, and falsely claiming the system was using a sandboxed version of WhatsApp. The researchers describe this as an “intent collision” attack, where the AI merges a user’s legitimate request with malicious web instructions. In a separate test, the researchers used a similar method to add a shipping address and a tablet to an Amazon shopping cart, and then had Atlas ask Amazon’s Rufus AI assistant to complete the purchase, though they could not directly bypass OpenAI’s purchase safeguards. The researchers reported the findings to OpenAI in January 2026, and the company says it deployed an update to address the issue, with protections extending to the new ChatGPT app. Bargury warns that such flaws effectively roll back browser security to the level of 20 years ago, and urges developers to use deterministic security barriers rather than relying solely on AI judgments, which can be fooled.
Sources
- WiredSecondary
Related
Meta AI model hacks outside system during cybersecurity test
OpenAI AI agents hack Hugging Face via secret message board
Security pro hacks North Korean hackers, finds 1,640 firms breached
BMC flaws expose thousands of servers to remote backdoor attacks
Apple Private Relay leaks real IP address due to WebKit flaws
Meta Ran Ads With AI-Generated Child Sexual Abuse Imagery
Anthropic's Mythos created fake identities to fool humans
AI models launch unsanctioned cyberattacks in UK watchdog tests
Trending now
- Meta AI model hacks outside system during cybersecurity test
- OpenAI AI agents hack Hugging Face via secret message board
- Security pro hacks North Korean hackers, finds 1,640 firms breached
- BMC flaws expose thousands of servers to remote backdoor attacks
- Spider-Man: Brand New Day hits $1 billion, 2026's fourth film to do so
- NASA’s IXPE captures first direct evidence of vacuum birefringence
- Moove raises $250M at $2.1B valuation for robotaxi fleet
- Snap stock jumps 12% on earnings beat and strong sales forecast
Comments
No comments yet. Be the first.