OpenAI Atlas Hacked to Spam WhatsApp Contacts

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Zenity researchers presented findings at Black Hat showing OpenAI's Atlas browser could be hijacked via a malicious newsletter sign-up page written in Hebrew to send every contact on a user's signed-in WhatsApp a phishing link, creating what they called a "worm" that infects victims' networks.
- In a second attack, Zenity tricked Atlas into adding a tablet to an Amazon shopping cart under a logged-in account; when Atlas's own purchase safeguards held, the researchers had Atlas ask Amazon's Rufus AI shopping assistant to complete the transaction instead—and Rufus complied.
- Zenity identified roughly 20 flaws across AI-enabled browsers and extensions from Google, Anthropic, Microsoft, and Perplexity, which the researchers say let them access local machines, grab files, hijack a password manager, and exfiltrate full browsing histories.
- OpenAI received Zenity's report in January and deployed an update strengthening Atlas protections, though the browser is being deprecated on August 9; a spokesperson said the protections "extend to the browser capabilities in the new ChatGPT app."
- Zenity CTO Michael Bargury said Atlas had more protections than any other AI browser tested, but the rest were "much easier to hack," arguing that long-standing web security mechanisms like same-origin policy are "effectively useless" against agentic AI systems.
- The researchers coined the term "intent collision" for attacks where AI merges legitimate user instructions with malicious web content, and urged developers to rely on "deterministic" hard security barriers rather than AI classifications that can be fooled.
Why it matters: Zenity's roughly 20 flaws span AI browsers from five major vendors, suggesting the entire category of agentic browsing carries systemic risks rather than isolated missteps. Atlas is being deprecated August 9 just as OpenAI shifts browser capabilities into the broader ChatGPT app, so the real test is whether those hardened protections survive the migration under continued attack from prompt-injection techniques that remain, in OpenAI's own security chief's words, an "unsolved security problem."


