Skip to content
worth noting Security

Zenity uncovered approximately 20 vulnerabilities in AI browsers from OpenAI, Google, Anthropic, Microsoft and Perplexity

only one source so far

Security firm Zenity uncovered approximately 20 vulnerabilities in AI-powered browsers and extensions from OpenAI, Google, Anthropic, Microsoft and Perplexity. The attacks allow access to the local computer, file theft, password manager takeovers and browsing history leaks.

Security firm Zenity (researchers Michael Bargury and Stav Cohen) presented findings at a security conference on approximately 20 vulnerabilities in AI-powered web browsers and extensions from OpenAI (the Atlas tool), Google, Anthropic, Microsoft and Perplexity. According to Zenity, the vulnerabilities allow attackers to access the local computer, download files, take over the password manager and leak the user’s entire browsing history.

As a proof-of-concept attack, the researchers had Atlas sign up for a newsletter on a page they had created themselves. The page contained instructions written in Hebrew that caused the agent to navigate to the user’s logged-in WhatsApp Web account and send the same message to all their contacts. The researchers describe this procedure as a “mass phishing campaign” with worm-like properties, and call the phenomenon in which AI mixes a legitimate user instruction with a malicious instruction from the web “intent collision”. According to their description, they managed to bypass security measures from OpenAI partly through a trustworthy-looking signup page, the use of Hebrew (outside the scope of English-language safety filters) and a false claim that this was a sandboxed version of WhatsApp Web with fake contacts.

In another test on Amazon, the researchers used the same method – a fake newsletter signup page – to make Atlas add a delivery address to the account and put a tablet in the cart. However, they were unable to bypass the safeguards for the purchase itself because of security measures from OpenOpenAI; they therefore ultimately asked Rufus, the AI assistant on Amazon, directly to complete the purchase. According to the researchers, Rufus had not been attacked or manipulated – it “merely” fulfilled the request because it considered it an instruction from the customer.

Zenity states that, of the tools tested, Atlas had the most security measures, yet they were still able to bypass them; according to the firm, the other tools were easier to hack. The findings were reported to OpenAI in January; according to a spokesperson for OpenAI, the company deployed an update strengthening protections in Atlas that also applies to browsing features in the new ChatGPT app. Atlas is due to be discontinued on 9 August, while the other tools mentioned remain vulnerable according to Zenity. The researchers recommend relying on deterministic security barriers for AI agents, not solely on the judgment or classification of the AI system itself, because they say it can almost always be tricked.

What changed

Why it matters

It appears that integrating AI agents into browsers weakens standard web security mechanisms (e.g. same-origin policy), and an attacker only needs to prepare a malicious page to make the agent act on the user’s behalf – send messages from their accounts, gain access to passwords or browsing history. For companies, this means that deploying such tools without hard technical limits on agent agency carries a real risk of data leaks and account abuse, even in products that have security measures – as the Atlas case demonstrated.

Two audiences, two different impacts

What this means

01

For individuals

Users of AI-powered browsers and extensions (e.g. Atlas, the Gemini browser, the Copilot browser, the Perplexity browser) may unknowingly trigger actions by visiting a malicious page, such as sending messages from their WhatsApp account to all their contacts or leaking saved passwords and browsing history.

What to do Do not give an AI browser tasks on unfamiliar or suspicious websites, and monitor sensitive accounts (WhatsApp, email, password manager) for unexpected actions.
More practical updates →
02

For a business

Companies deploying agentic AI browsers risk account takeovers, data leaks and attacks spreading among users’ contacts; according to Zenity, they need to rely on hard technical barriers, not on the judgment of the AI system, because it can almost always be tricked.

Risks and compliance
What to decide Before deploying AI browsers or extensions in a company, check with the vendor whether it uses deterministic security barriers, rather than relying solely on AI judgment, and monitor whether the product has received a fix.
More business impacts →
AI agents Security vulnerabilities OpenAI Atlas prompt injection Web browsers WhatsApp

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
Wired — AI section independent context · first detected OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts