Security researchers at Zenity have uncovered multiple vulnerabilities in AI-powered browsers, including OpenAI’s Atlas. The team identified more than a dozen flaws that could allow attackers to manipulate the browser for malicious actions, such as spamming WhatsApp contacts or making unauthorized purchases.
In one demonstration, researchers successfully got OpenAI’s Atlas to complete an Amazon purchase without the user’s consent. The exploit did not require direct access to the user’s device, highlighting the severity of the issue. The findings point to a broader risk in AI-integrated web tools, where autonomous actions can be hijacked.
The vulnerabilities stem from how these browsers process instructions and interact with external services. Attackers could embed hidden commands into web content, which the AI browser would then execute automatically. This includes sending messages, accessing personal data, or triggering financial transactions.
Zenity’s team noted that the flaws are not unique to OpenAI’s Atlas. Other AI browsers with similar architectures share comparable weaknesses. The research indicates that the rush to integrate AI features into everyday tools may have overlooked critical security measures.
The attack method relies on tricking the AI into believing it is following legitimate user commands. By crafting specific prompts or exploiting parsing gaps, attackers can redirect the browser’s actions. The Amazon purchase case is a clear example of how these exploits can have real-world financial impact.
OpenAI has not yet issued a public response to the findings. Zenity has reportedly disclosed the vulnerabilities to the affected companies, but the details of any patches remain unclear. Users are advised to limit the permissions granted to AI browser extensions and review their transaction histories regularly.
The broader implication is that AI browsers introduce a new attack surface that traditional security tools may not fully cover. As these tools become more common, developers will need to prioritize secure design over feature speed. Until then, users should approach AI-driven automation with caution, especially when it involves sensitive actions like payments or messaging.





