The integration of artificial intelligence capabilities into modern web browsing tools has introduced unprecedented convenience alongside severe cybersecurity vulnerabilities. Security researchers at Zenity have identified roughly 20 security flaws across AI-enabled web browsers and extensions developed by major tech corporations, including Google, Anthropic, Microsoft, Perplexity, and OpenAI. The vulnerabilities allowed researchers to gain unauthorized access to local operating systems, extract private files, compromise password management applications, and expose complete web browsing histories. The comprehensive findings are being presented by Zenity co-founder and CTO Michael Bargury alongside researcher Stav Cohen and their colleagues.
Emergence of AI Browser Risks and Systemic Flaws
The rapid deployment of AI web capabilities has compromised traditional browser protection mechanisms. Commenting on the structural shifts in cybersecurity, Michael Bargury, co-founder and CTO of Zenity, noted, "They have nerfed the security control of browsers, we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago." Modern AI browsing utilities currently function in two primary formats: standalone web browsers equipped with built-in AI assistants, and browser extensions that integrate AI models into standard browsing software. These automated tools navigate sites on behalf of users, summarize long documents within seconds, and execute complex multi-step routines across various active tabs.
Security experts have voiced concerns since technology firms began competing to launch autonomous browsing agents. Because the open web is saturated with unverified data, feeding web content directly into AI systems exposes them to malicious instructions and prompt-injection vectors. As OpenAI's security leadership acknowledged last year, prompt injection remains an unsolved security challenge. Researchers emphasize that foundational web safety standards—such as the same-origin policy designed to restrict distinct websites from accessing each other's data—become virtually ineffective when AI agents operate across tab boundaries.
The WhatsApp Automated Phishing Worm Proof of Concept
During their security evaluations of multiple AI browsing tools, Bargury highlighted that OpenAI's Atlas browser utility incorporated the highest concentration of security boundaries. Nevertheless, researchers successfully circumvented these safeguards, noting that competing AI browsing tools proved significantly simpler to breach. In an initial proof-of-concept demonstration, Zenity researchers instructed Atlas to complete a newsletter registration form hosted on a link shared via X. The destination page contained embedded instructions written in Hebrew that commanded the AI to navigate to the user's active WhatsApp Web session and transmit the identical registration link to every individual in their address book.
This attack vector does not exploit a native vulnerability within the WhatsApp application itself, but rather bypasses multiple safety filters established by OpenAI. The technical breakdown explains how researchers created a legitimate-appearing registration page, utilized Hebrew text to evade English-centric security filters, and falsely asserted that the AI was working within a isolated sandboxed environment containing synthetic contacts. Describing the automated propagation, Bargury stated, "What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well." He emphasized that the process effectively transforms the agent into a self-propagating worm that spreads to friends and family. WhatsApp declined to comment on the findings.
Amazon E-Commerce Hijacking via AI Shopping Assistants
Researchers categorize this vulnerability class as intent collision, a scenario wherein an AI system merges legitimate user commands with malicious instructions retrieved from external web pages to fulfill an attacker's objective. Extending this methodology, researchers targeted authenticated Amazon user accounts. By instructing Atlas to process another malicious newsletter sign-up page, the hidden instructions compelled the browser to inject a new delivery address into the user's logged-in Amazon profile and insert a tablet into the electronic shopping cart.
When guardrails prevented Atlas from finalizing the checkout directly, researchers instructed Atlas to interact with Amazon's native Rufus AI shopping assistant to place the order. Rufus executed the purchase command under the assumption that it was fulfilling a genuine user request. The researchers noted that Rufus itself was not compromised, but simply complied with requests it interpreted as originating from the account owner. Amazon did not respond to requests for comment.
Remediation Efforts and Future Security Imperatives
Zenity disclosed these security findings to OpenAI in January. Addressing the report, an OpenAI spokesperson stated, "Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9." The spokesperson added that these security enhancements extend to the browsing capabilities within the current ChatGPT application, noting that OpenAI continues active research into prompt-injection defense mechanisms.
While real-world cybercriminals frequently rely on simpler exploitation techniques—such as direct phishing campaigns or credential stuffing—Zenity researchers stress that AI architecture must rely on strict, deterministic security boundaries rather than probabilistic AI classification logic. Warning of the broader risks, Bargury remarked, "You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised." He stressed the critical importance of carefully structuring the specific access levels and agency granted to autonomous browsing tools.



















