CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3953

As cited

Copy frozen at (site build).

ai security

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Zenity researchers discovered over a dozen vulnerabilities in AI browsing tools, including the ability to hijack OpenAI's Atlas browser to perform unauthorized actions such as making Amazon purchases. The flaws could allow attackers to abuse the tool to send unwanted messages through WhatsApp or perform other malicious transactions on behalf of users.

Why it matters: Organizations deploying AI browsers for automated tasks face supply chain and fraud risk if these agents can be manipulated to access user accounts and execute purchases or communications without authorization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Security researchers at Zenity identified over a dozen vulnerabilities in browsers powered by artificial intelligence (AI) and showed that OpenAI’s Atlas could be forced to complete an unapproved Amazon transaction. The flaws could let attackers manipulate the browser to send spam messages through the victim’s WhatsApp contacts.

Why it matters: Users of OpenAI’s Atlas browser and their WhatsApp contacts are at risk of unauthorized purchases and spam, so practitioners should monitor for AI browser hijacking attempts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary