Skip to main content
OpenAI browser flaw: prompt injection vulnerability spamming WhatsApp contacts, cybersecurity risk.

Editorial illustration for OpenAI Browser Flaw Could Spam WhatsApp Contacts Via Prompt Injection

OpenAI Browser Flaw Lets Hackers Spam WhatsApp

OpenAI Browser Flaw Could Spam WhatsApp Contacts Via Prompt Injection

4 min read

Researchers at security firm Zenity say OpenAI's Atlas browser can be manipulated into sending unwanted WhatsApp messages to dozens of a user's contacts or completing purchases on Amazon without permission. The findings, unveiled today at the Black Hat cybersecurity conference in Las Vegas, cover roughly 20 separate flaws Zenity uncovered across AI-enabled browsers and browser extensions built by OpenAI, Google, Anthropic, Microsoft, and Perplexity.

The vulnerabilities go beyond spam messages. Zenity's team found ways to reach into local machines, pull files off a device, hijack a password manager, and expose a person's full browsing history. The research points to a pattern across the industry: as companies race to bolt AI agents onto web browsers, letting them read pages, fill out forms, and act across multiple tabs, they're also reopening security gaps that browser makers spent two decades closing.

Zenity cofounder and CTO Michael Bargury is presenting the results alongside colleague Stav Cohen and others. Their work lands at a moment when browser AI agents are shifting from novelty features into everyday tools, handling tasks like summarizing pages and executing multistep actions, often without a person double-checking each step.

OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, according to new research presented today at the Black Hat cybersecurity conference in Las Vegas.

Why this matters

Zenity's demo landed at Black Hat, not a random blog post, and it's aimed at the whole category of AI browsers, not just Atlas. That matters for anyone building or deploying agentic tools right now: OpenAI, Google, Anthropic, and Microsoft all got flagged in the same research sweep. If the flaw set is that widespread, this isn't a bug OpenAI can patch its way out of by next quarter.

It's an architectural bet, letting an AI system read and act on arbitrary web content, and that bet currently loses to anyone who can plant a malicious instruction in a webpage. OpenAI's own security lead called prompt injection "unsolved" last year, and researchers have been saying the same thing for longer than that. For teams shipping agents that can send messages or place orders on a user's behalf, the practical takeaway is blunt: don't grant purchase or contact-list permissions to a browser agent until someone can show you a real fix, not a patch.

Watch whether OpenAI, Google, and Anthropic respond with actual containment measures or just quieter permission prompts.

Common Questions Answered

What specific vulnerabilities did Zenity researchers discover in OpenAI's Atlas browser?

Zenity researchers found that OpenAI's Atlas browser could be manipulated through prompt injection attacks to send unwanted WhatsApp messages to dozens of contacts or complete unauthorized purchases on Amazon without user permission. These security flaws allow attackers to bypass the browser's security protections and trick the AI system into performing actions the user did not authorize.

How many AI-enabled browsers and extensions were affected by the flaws Zenity uncovered?

Zenity discovered approximately 20 separate flaws across AI-enabled browsers and browser extensions built by multiple major companies including OpenAI, Google, Anthropic, Microsoft, and Perplexity. This widespread vulnerability across multiple vendors indicates a systemic issue rather than isolated bugs in individual products.

Why is the architectural approach of agentic AI tools a concern according to the research?

The research suggests that the fundamental architectural design of letting AI systems read and act on arbitrary web content creates inherent security risks that cannot be easily patched in the short term. This architectural bet represents a deeper challenge for the industry than simple bug fixes, as it involves how these AI browsers are fundamentally designed to interact with web content.

Where were Zenity's security findings about AI browser vulnerabilities presented?

Zenity unveiled their research at the Black Hat cybersecurity conference in Las Vegas, which is a prestigious venue for security research rather than a random blog post. The choice to present at Black Hat underscores the significance of the findings and their relevance to the entire category of AI browsers being developed by major technology companies.

LIVE02:51OpenAI's AI Agents Used Message Board to Plan Hacking Spree