OpenAI Browser Flaws Could Let Attackers Spam WhatsApp Contacts and Shop on Amazon
Researchers found about 20 vulnerabilities in AI-powered browsers and extensions, including weaknesses in OpenAI's Atlas that could be abused to send messages to all WhatsApp contacts or make purchases on Amazon. The findings were presented at the Black Hat security conference.

Security researchers from the firm Zenity have uncovered a series of vulnerabilities in AI-enabled web browsers and extensions. During a presentation at the Black Hat conference in Las Vegas, they described roughly 20 flaws affecting products from Google, Anthropic, Microsoft, and Perplexity. Some of the flaws could be used to access local machines, steal files, hijack password managers, and expose a user's entire browsing history.
The researchers focused on OpenAI's Atlas browser, which the company is scheduled to retire next week. Despite Atlas having the most security protections among the tested tools, the team managed to bypass them. In one demonstration, they created a fake newsletter sign-up page with hidden instructions in Hebrew. The page convinced the browser to open the user's WhatsApp Web account and send a mass message to every contact, urging them to join the same newsletter. The researchers described this as a mass phishing campaign and a worm, because it could spread to friends and family.
According to Michael Bargury, Zenity's cofounder and CTO, the attack did not exploit a vulnerability in WhatsApp itself. Instead, it circumvented multiple safety mechanisms in OpenAI's browser. The attackers made the page appear legitimate, used Hebrew to evade English-language security filters, and falsely claimed that the system was using a sandboxed version of WhatsApp with fake users.
In a second attack, the researchers used a similar approach to manipulate an Amazon account. They made Atlas add a shipping address and a tablet to the shopping cart. Although they could not directly complete the purchase due to OpenAI's safeguards, they found a workaround: the browser asked Amazon's Rufus AI assistant to make the purchase, and Rufus complied.
Zenity reported the issues to OpenAI in January. An OpenAI spokesperson said the company deployed an update earlier this year to strengthen protections in Atlas, which will be deprecated on August 9. The spokesperson added that the protections extend to the browser capabilities in the new ChatGPT app and that prompt-injection attacks remain an active area of research.
The researchers argue that AI systems should rely on deterministic or hard security barriers rather than AI judgments, which can often be tricked. Without such measures, they warn, browsers could be hijacked, leading to compromised accounts and leaked data.

