Security researchers uncover vulnerabilities in OpenAI ChatGPT Atlas browser

Security researchers at Zenity Labs have identified critical vulnerabilities in OpenAI’s ChatGPT Atlas browser that could allow malicious actors to hijack user accounts to send phishing messages via WhatsApp. The exploit, presented at the Black Hat USA 2026 conference on 5 August, utilises a “PleaseFix” attack chain to bypass established security guardrails and manipulate the browser’s agentic workflow.

Exploitation Of Agentic Capabilities

The flaw targets the browser’s agentic functions, which were introduced when ChatGPT Atlas launched on 21 October 2025. By embedding malicious instructions within seemingly benign web content, attackers can trick the browser into executing unauthorised tasks, including sending messages from the user’s personal accounts.

The main risk is that it collapses the boundary between the data and the instructions: It could turn an AI agent in a browser from a helpful tool to a potential attack vector against the user.

Researchers further demonstrated that the exploit can be extended beyond messaging to include financial fraud. In a controlled test, they manipulated the browser to utilise Amazon’s AI assistant, Rufus, to complete unauthorised purchases using a victim’s stored credit card information.

Broader Implications For AI Browsing

The rise of agentic browsers that navigate the web and interact with applications introduces significant new security risks for everyday users. Unlike traditional web browsers that merely display information, these tools interpret content as direct instructions, creating a blurred line between intended user actions and automated malicious commands.

This incident highlights the growing concern regarding prompt injection and jailbreak attacks in modern AI-enabled software. As developers continue to integrate autonomous agents into daily productivity tools, users should remain vigilant regarding the permissions granted to these browsers while security patches are developed to mitigate the “PleaseFix” exploit chain.

Related Articles

Most Read