Skip to content
WIRED·

🔒OpenAI's Atlas Bypassed by Hackers, Security Flaws Found

Hackers bypassed OpenAI's supposedly secure browser

TL;DR

Zenity researchers discovered over 20 security vulnerabilities in leading AI-enabled browsers, including OpenAI's Atlas. Despite robust protections, they could still manipulate the system to spam contacts and make unauthorized purchases.

Security firm Zenity found that hackers can bypass even the most secure AI web browser tools like OpenAI's Atlas. Researchers demonstrated how flaws allow access to local machines, grabbing files, taking over password managers, and leaking browsing history. This is a wake-up call for developers using AI-integrated browsers in sensitive environments. The findings were presented at Black Hat 2023, highlighting the need for deterministic security barriers when designing AI systems.

OpenAI's Atlas Bypassed by Hackers, Security Flaws Found — WIRED

Key Points

1

Researchers found over 20 flaws in leading AI-enabled browsers, including OpenAI's Atlas (January 2023).

2

Hackers can bypass security mechanisms to manipulate systems like signing up for newsletters and adding items to shopping carts without purchases.

3

The attacks work by exploiting untrusted data exposure to AI systems, enabling prompt-injection attacks on local machines and browsing history.

4

OpenAI responded with an update to strengthen protections in Atlas after researchers reported findings in January 2023.

5

Zenity recommends deterministic security barriers over relying on AI judgments for critical operations like web browsing.

Why It Matters

Developers using OpenAI's Atlas or similar AI-integrated browsers should be wary of untrusted data exposure and prompt-injection attacks. This affects anyone handling sensitive information online, especially in environments where local machine access is a risk.

OpenAIAtlasZenityBlack HatAI Security

Frequently Asked Questions

Why does this matter?

Developers using OpenAI's Atlas or similar AI-integrated browsers should be wary of untrusted data exposure and prompt-injection attacks. This affects anyone handling sensitive information online, especially in environments where local machine access is a risk.

What happened?

Zenity researchers discovered over 20 security vulnerabilities in leading AI-enabled browsers, including OpenAI's Atlas. Despite robust protections, they could still manipulate the system to spam contacts and make unauthorized purchases.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,647 builders reading daily.

Also get