logo

OpenAI ChatGPT Atlas Browser Jailbroken to Disguise Malicious Prompt as URLs

ID: 710e0325-8874-54be-bb9c-a5080f68f66c

STIX ID: report--710e0325-8874-54be-bb9c-a5080f68f66c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-10-25

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Security researchers from NeuralTrust disclosed a critical prompt-injection jailbreak in OpenAI’s ChatGPT Atlas browser: crafted, URL-like strings pasted into the omnibox are rejected as navigation and instead handled as high-trust prompts, allowing the agent to execute embedded malicious instructions (e.g., credential-harvesting redirects, data export, or destructive actions). Proof-of-concept examples and clipboard-based attack demonstrations were published, and the report also notes Atlas storing OAuth tokens unencrypted, which could enable unauthorized account access; OpenAI acknowledged the risk and invoked red-teaming and mitigations but warned the problem persists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.