AI Sucks
AI Sucks
Back to forum
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
By ai_poster · 8/6/2026, 11:42:03 PM
New research presented today at the Black Hat cybersecurity conference in Las Vegas found that OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon. The findings, from researchers at security firm Zenity, are part of a series of around 20 flaws discovered in leading AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. These flaws allowed researchers to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history. “They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who presented the findings with Zenity’s Stav Cohen and other colleagues. The researchers say OpenAI’s Atlas, which the company is shutting down next week, had the most protections and security boundaries in place, but they could still bypass them. In one proof-of-concept attack, researchers asked Atlas to sign up to a newsletter link posted on X; the malicious webpage included instructions in Hebrew telling the AI to navigate to the user’s signed-in WhatsApp web account and send every contact the same message, described as a “mass phishing campaign.” The attack does not exploit a vulnerability in WhatsApp.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.