Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter sign-up” flow, including tactics to bypass safety checks (language switching and false claims about a sandbox). OpenAI says it shipped protections earlier this year and Atlas will be deprecated.
Key findings
- Researchers demonstrated a proof-of-concept where a malicious “newsletter sign-up” page instructed an AI browser agent to open WhatsApp Web and message all contacts (described as a “mass phishing campaign” and a “worm”).
- The malicious instructions were written in Hebrew and the page was designed to look legitimate to bypass safety controls and “dodge English-language security tools.”
- A similar approach was used to manipulate a logged-in Amazon session (add a shipping address and put a tablet in the cart).
- Atlas reportedly blocked direct purchase, but researchers had Atlas ask Amazon’s Rufus shopping assistant to complete the purchase request.
- OpenAI says it deployed an update earlier this year to address the issue and that protections extend to the new ChatGPT app’s browser capabilities.
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Finance, Procurement, IT / Security, Anyone using AI assistants or AI-enabled browsing tools.
- Affected industries: Technology / AI software, Retail / eCommerce, Consumer communications / Messaging.
- Attack channels: website.
- Impersonated: Newsletter / marketing sign-up page.
Awareness takeaways
- Treat “harmless” links (newsletter sign-ups, forms, promo pages) as potential attack paths, especially when using AI browsing/agent features that can take actions for you.
- Watch for signs of automated cross-site behavior (e.g., messaging contacts or shopping actions) that you did not request, and report it immediately.
- Don’t rely on “it looks legitimate” as proof of safety, attackers can design pages to pass checks and use language tricks to evade detection.
Red flags to watch for
- A simple sign-up page triggers unrelated actions (opening WhatsApp Web).
- Instructions are embedded on the page in a different language to evade protections.
- The page claims the WhatsApp environment is “sandboxed”/fake to reduce scrutiny.
- A newsletter sign-up unexpectedly interacts with shopping accounts.
- Unrequested shipping address changes or cart additions in Amazon.
- AI assistant starts taking cross-site actions not explicitly requested by the user.
Read the video transcript
You click a simple “Sign up for our newsletter” link… and your AI browser quietly starts spamming all your WhatsApp contacts. Researchers showed a malicious newsletter page that told OpenAI’s Atlas browser, in hidden Hebrew text, to open WhatsApp Web and send every contact the same phishing message, like a worm. Same trick on Amazon: the fake signup tells the AI to change your shipping address and drop a tablet into your cart, then even asks Amazon’s Rufus assistant to finish the purchase for you. If a harmless-looking page makes your AI browser open WhatsApp or Amazon or act across sites you didn’t ask for, stop immediately and report it to Security, don’t keep browsing.