OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

https://media.wired.com/photos/6a7212f79008189a91ab1d18/191:100/w_1280,c_limit/Security_OpenAI%E2%80%99s%20Browser%20Could%20Be%20Hijacked%20to%20Send%20WhatsApp%20Spam_v1.jpg

OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, according to new research presented today at the Black Hat cybersecurity conference in Las Vegas.

The Atlas findings, from researchers at security firm Zenity, are part of a broad series of flaws the company discovered in leading AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. The researchers found around 20 flaws, which allowed them to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history.

“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings at the security conference with Zenity’s Stav Cohen and other colleagues.

...

Copyright of this story solely belongs to wired.com. To see the full text click HERE

Read more