ARTFEED — Contemporary Art Intelligence

OpenAI's Atlas Browser Vulnerable to Hijacking, Researchers Find

ai-technology · 2026-08-06

Security researchers at Zenity have identified over a dozen vulnerabilities in AI-powered browsers, including OpenAI's Atlas. These flaws could allow attackers to hijack the browser to perform unauthorized actions, such as making purchases on Amazon or sending spam messages via WhatsApp. The findings highlight significant security risks in the emerging category of AI-integrated web browsers, which are designed to automate tasks on behalf of users. Zenity's research demonstrates that despite advanced AI capabilities, these browsers lack robust security measures, potentially exposing users to financial and privacy threats. The vulnerabilities were discovered in Atlas, which is built on the Chromium engine and integrates OpenAI's language models to assist with browsing tasks. The researchers successfully exploited the flaws to make an unauthorized Amazon purchase, proving the practical impact of the weaknesses. OpenAI has been notified of the issues, but the company has not yet released a public statement. The findings underscore the need for stronger security protocols in AI-driven tools as they become more prevalent in everyday digital activities.

Key facts

  • Zenity researchers found more than a dozen flaws in AI browsers.
  • OpenAI's Atlas browser was exploited to make an unauthorized Amazon purchase.
  • The vulnerabilities could also allow hijacking to spam WhatsApp contacts.
  • Atlas is built on Chromium and integrates OpenAI's language models.
  • The research highlights security risks in AI-powered browsers.
  • OpenAI has been notified of the vulnerabilities.
  • The findings were reported by Wired.
  • The exact date of the research is not specified.

Entities

Institutions

  • Zenity
  • OpenAI
  • Amazon
  • WhatsApp
  • Wired

Sources