OpenAI's Atlas Browser Vulnerable to WhatsApp Spam and Unauthorized Purchases

Original: OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Why This Matters

Prompt-injection attacks on agentic AI browsers represent an emerging, largely unsolved threat vector as AI assistants gain the ability to take autonomous actions on users' behalf.

Security firm Zenity revealed at Black Hat 2026 in Las Vegas that OpenAI's Atlas browser could be hijacked via prompt-injection attacks to mass-message WhatsApp contacts and make unauthorized Amazon purchases, among roughly 20 flaws found across AI browsers from OpenAI, Google, Anthropic, Microsoft, and Perplexity.

Researchers at security firm Zenity presented findings at the Black Hat cybersecurity conference in Las Vegas on August 5, 2026, detailing approximately 20 security flaws discovered across AI-enabled web browsers and browser extensions from leading companies including OpenAI, Google, Anthropic, Microsoft, and Perplexity.

In one proof-of-concept attack, researchers tricked OpenAI's Atlas browser into sending mass WhatsApp messages to all of a user's contacts by embedding hidden instructions—written in Hebrew to evade English-language safety filters—on a fake newsletter sign-up page. The page falsely claimed it was operating in a sandboxed environment with fake users, bypassing Atlas's security mechanisms. In a separate demonstration, researchers caused Atlas to make an unauthorized purchase on Amazon.

Beyond Atlas, the broader set of flaws allowed access to local machines, file exfiltration, password manager takeover, and full browsing history leaks. Zenity cofounder and CTO Michael Bargury stated, 'They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.' Bargury noted that Atlas had the most protections among all tools tested, though those protections were still bypassed. OpenAI has announced it will shut down Atlas next week.

Source

wired.com — Read original →