Updated
Updated · WIRED · Aug 5
Zenity Shows 20 AI Browser Flaws, Hijacking OpenAI Atlas for WhatsApp Spam
Updated
Updated · WIRED · Aug 5

Zenity Shows 20 AI Browser Flaws, Hijacking OpenAI Atlas for WhatsApp Spam

2 articles · Updated · WIRED · Aug 5

Summary

  • Black Hat researchers showed Atlas could be tricked into sending phishing messages to dozens of WhatsApp contacts and into completing an Amazon purchase without the user’s intent.
  • Zenity said the attacks relied on “intent collision,” where Atlas merged a legitimate newsletter signup with hidden malicious instructions on the webpage, including Hebrew text that slipped past safeguards.
  • OpenAI said it fixed the reported issue earlier this year after Zenity disclosed it in January, and said the added protections also apply to browser features in the new ChatGPT app.
  • Around 20 flaws across AI-enabled browsers and extensions from OpenAI, Google, Anthropic, Microsoft and Perplexity let researchers access local machines, steal files, seize a password manager and expose browsing histories.
  • Atlas, which OpenAI plans to shut down on August 9, had the strongest defenses Zenity tested, underscoring broader warnings that prompt injection remains an unsolved risk for AI agents on the web.

Insights

Will 'intent collision' make AI-powered web browsing too dangerous to use, or can strict security controls save the agentic web?
Could invisible text on a seemingly harmless webpage secretly hijack your AI assistant to drain your accounts?