Researchers at security firm Zenity presented findings at the Black Hat conference in Las Vegas showing that AI-enabled web browsers can be hijacked through prompt-injection attacks. The team, including cofounder and CTO Michael Bargury and researcher Stav Cohen, found around 20 flaws across AI browsers and browser extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity. The flaws allowed them to access local machines, grab files, take over a password manager, and leak entire browsing histories. Bargury said vendors have weakened browser security controls to the point where attacks reminiscent of 20 years ago are possible again, and that classic defenses like the same-origin policy become effectively useless.
OpenAI's Atlas browser had the strongest protections of the tools tested, yet the researchers still bypassed them. In one proof of concept, Atlas was asked to sign up for a newsletter via a link posted on X. The malicious sign-up page contained hidden instructions written in Hebrew — chosen to dodge English-language safety filters — directing the AI to open the user's logged-in WhatsApp Web account and send every contact the same message, creating a self-propagating worm the researchers likened to a mass phishing campaign. The attackers also made the page look legitimate and falsely claimed the system was operating in a sandboxed WhatsApp environment. Zenity calls this pattern "intent collision," where the AI merges a legitimate user request with malicious web content.
In a second attack, the team used a similar fake newsletter page to make Atlas add a shipping address to a logged-in Amazon account and place a tablet in the shopping cart. When OpenAI's safeguards blocked the actual purchase, the researchers simply had Atlas ask Amazon's Rufus AI shopping assistant to complete the order — which it did, treating the request as coming from the customer. Rufus itself was not injected; it was merely asked and complied.
Zenity reported the findings to OpenAI in January. OpenAI said it deployed an update addressing the issue and strengthening Atlas protections, which also extend to browser capabilities in the new ChatGPT app; Atlas is being deprecated on August 9. The researchers acknowledge the attacks are complex and criminals have easier options, but argue that AI systems need deterministic, hard security barriers rather than AI-based judgments that can nearly always be fooled. They urge caution about how much access and agency browser agents are granted, since a hijacked browser can compromise accounts and leak data.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.