OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
ID: 83186db5-04d8-56b5-bcab-47d2877a11ca
STIX ID: report--83186db5-04d8-56b5-bcab-47d2877a11ca
Feed Name: WIRED Security
Researchers demonstrated an "intent collision" attack where malicious instructions embedded in webpages combined with legitimate user inputs let an AI browser agent (Atlas) perform unauthorized actions — adding addresses and items to accounts and asking Amazon's Rufus assistant to complete purchases. The findings were reported to OpenAI, mitigations were applied and Atlas will be deprecated; researchers warn that deterministic security barriers are needed because AI judgment can be bypassed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
