OpenAI Atlas browser flaws let hackers spam WhatsApp contacts
AI web browser tricked into mass WhatsApp spam, researchers warn at Black Hat
Security firm Zenity revealed at Black Hat 2024 that OpenAI’s Atlas AI browser could be weaponized to spam WhatsApp contacts or manipulate Amazon accounts via prompt-injection attacks. Researchers bypassed multiple safety mechanisms—including sandboxing and language filters—to trigger malicious actions like mass messaging or unauthorized purchases. Despite Atlas’s advanced protections, they exploited "intent collision" where legitimate user instructions merged with malicious web inputs to bypass safeguards.
The team demonstrated two proof-of-concepts: a Hebrew-language newsletter sign-up page tricked Atlas into sending identical messages to all WhatsApp contacts (effectively a worm-like phishing campaign), and a fake Amazon newsletter page that added shipping addresses and items to carts. While they couldn’t complete purchases directly, they exploited Amazon’s Rufus AI assistant to initiate orders. Atlas, now discontinued by OpenAI, was the most secure among tested AI browsers—yet still vulnerable. The findings highlight systemic risks in AI agents navigating untrusted web data, where traditional security policies like same-origin protections are rendered ineffective.
- Zenity bypassed OpenAI Atlas’s security to spam WhatsApp contacts via Hebrew-language prompt injection
- Attackers could manipulate Amazon accounts via Atlas to add items to carts, exploiting Rufus AI assistant
- Researchers tested 20 flaws across AI browsers from OpenAI, Google, Anthropic, Microsoft, and Perplexity
Why It Matters
AI web browsers’ agentic capabilities introduce new attack surfaces, turning trusted tools into vectors for mass phishing and financial fraud.