OpenAI’s Atlas web browser, scheduled for deprecation on August 9, has been revealed as vulnerable to significant security bypasses. Research presented today at the Black Hat conference in Las Vegas by security firm Zenity demonstrated how the system could be manipulated into spamming WhatsApp contacts and making unauthorized Amazon purchases.
The Vulnerability of 'Intent Collision'
Zenity researchers identified approximately 20 flaws across leading AI-enabled browsers and extensions, including those from Google, Microsoft, and Anthropic. The most notable attack involved a concept dubbed "intent collision," where the AI merges a user's legitimate instructions with malicious commands embedded in untrusted web data.
In one proof-of-concept, researchers directed Atlas to sign up for a newsletter. The malicious page contained instructions written in Hebrew—a tactic used to evade English-centric security tools—ordering the AI to access the user’s signed-in WhatsApp Web account and broadcast a phishing message to every contact.
Exploiting Amazon and Rufus
The researchers also successfully manipulated the browser into adding items to an Amazon cart and modifying shipping addresses. While OpenAI’s internal safety measures initially blocked the final purchase, the researchers bypassed this by directing Atlas to interact with Rufus, Amazon’s own AI shopping assistant. Rufus, perceiving the request as coming from the legitimate user, complied with the instruction to finalize the order.
“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity.
OpenAI responded that they deployed updates to address these issues earlier this year, noting that these protections are also integrated into the browser capabilities of the current ChatGPT application. The researchers emphasized that AI systems require deterministic security barriers rather than relying solely on AI-based classifications, which remain susceptible to manipulation.