Security researchers at Zenity have uncovered more than a dozen vulnerabilities in AI-powered browsers, including OpenAI's Atlas, that could allow attackers to hijack the browser and perform actions such as making unauthorized purchases on Amazon and sending spam messages to WhatsApp contacts.
The Discovery
Zenity's research team identified multiple security weaknesses in several AI browsers, with OpenAI's Atlas being the most prominent. The vulnerabilities stem from how these browsers handle automation commands and permissions. Attackers could exploit these flaws without needing physical access to the device, relying instead on malicious web content or compromised third-party services.
In a proof-of-concept demonstration, Zenity researchers showed how they could command Atlas to add a product to an Amazon cart and complete the purchase using stored payment credentials. They also managed to trigger the browser to send WhatsApp messages to all contacts, simulating a spam attack that could spread malware or phishing links.
How the Attack Works
The attacks leverage the same automation features that make AI browsers useful. Atlas, like other AI browsers, can execute multi-step tasks based on natural language prompts. By injecting malicious instructions, attackers can hijack this pipeline. The researchers demonstrated several exploit scenarios:
These exploits require no special permissions beyond what the browser already has. The automation features are designed to act on behalf of the user, making them a powerful vector for abuse.
Why This Matters
The vulnerabilities represent a serious risk for users of AI browsers, which are gaining popularity for their ability to automate tasks like online shopping, email management, and social media interaction. If exploited in the wild, the flaws could lead to financial loss, privacy breaches, and reputational damage for individuals and businesses.
For OpenAI, the findings underscore the challenge of balancing convenience with security in AI agents. Atlas is still in early access, but similar vulnerabilities could emerge in other AI browsers from companies like Google and Microsoft. The attack surface is broad: any browser that can execute automated tasks on behalf of a user is susceptible if permissions are not tightly controlled.
Zenity has responsibly disclosed the vulnerabilities to OpenAI, which is now developing patches. Users of AI browsers should ensure they are running the latest updates and be cautious about granting broad automation permissions. The incident also highlights the need for industry-wide security standards for AI agents that interact with financial systems and communication platforms.



