AI Web Browsers Vulnerable to Exploitation, Enabling WhatsApp Contact Hijacking and Amazon Cart ManipulationAI
6 Aug 2026, 5:21 am (2 hours ago)· 0

AI Web Browsers Vulnerable to Exploitation, Enabling WhatsApp Contact Hijacking and Amazon Cart Manipulation

Cybersecurity researchers have uncovered nearly two dozen flaws across AI-integrated web browsers, demonstrating how malicious actors could manipulate AI agents into hijacking WhatsApp accounts and placing unauthorized e-commerce orders.

The integration of artificial intelligence capabilities into modern web browsing tools has introduced unprecedented convenience alongside severe cybersecurity vulnerabilities. Security researchers at Zenity have identified roughly 20 security flaws across AI-enabled web browsers and extensions developed by major tech corporations, including Google, Anthropic, Microsoft, Perplexity, and OpenAI. The vulnerabilities allowed researchers to gain unauthorized access to local operating systems, extract private files, compromise password management applications, and expose complete web browsing histories. The comprehensive findings are being presented by Zenity co-founder and CTO Michael Bargury alongside researcher Stav Cohen and their colleagues.

Emergence of AI Browser Risks and Systemic Flaws

The rapid deployment of AI web capabilities has compromised traditional browser protection mechanisms. Commenting on the structural shifts in cybersecurity, Michael Bargury, co-founder and CTO of Zenity, noted, "They have nerfed the security control of browsers, we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago." Modern AI browsing utilities currently function in two primary formats: standalone web browsers equipped with built-in AI assistants, and browser extensions that integrate AI models into standard browsing software. These automated tools navigate sites on behalf of users, summarize long documents within seconds, and execute complex multi-step routines across various active tabs.

Also read

Security experts have voiced concerns since technology firms began competing to launch autonomous browsing agents. Because the open web is saturated with unverified data, feeding web content directly into AI systems exposes them to malicious instructions and prompt-injection vectors. As OpenAI's security leadership acknowledged last year, prompt injection remains an unsolved security challenge. Researchers emphasize that foundational web safety standards—such as the same-origin policy designed to restrict distinct websites from accessing each other's data—become virtually ineffective when AI agents operate across tab boundaries.

The WhatsApp Automated Phishing Worm Proof of Concept

During their security evaluations of multiple AI browsing tools, Bargury highlighted that OpenAI's Atlas browser utility incorporated the highest concentration of security boundaries. Nevertheless, researchers successfully circumvented these safeguards, noting that competing AI browsing tools proved significantly simpler to breach. In an initial proof-of-concept demonstration, Zenity researchers instructed Atlas to complete a newsletter registration form hosted on a link shared via X. The destination page contained embedded instructions written in Hebrew that commanded the AI to navigate to the user's active WhatsApp Web session and transmit the identical registration link to every individual in their address book.

This attack vector does not exploit a native vulnerability within the WhatsApp application itself, but rather bypasses multiple safety filters established by OpenAI. The technical breakdown explains how researchers created a legitimate-appearing registration page, utilized Hebrew text to evade English-centric security filters, and falsely asserted that the AI was working within a isolated sandboxed environment containing synthetic contacts. Describing the automated propagation, Bargury stated, "What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well." He emphasized that the process effectively transforms the agent into a self-propagating worm that spreads to friends and family. WhatsApp declined to comment on the findings.

Amazon E-Commerce Hijacking via AI Shopping Assistants

Researchers categorize this vulnerability class as intent collision, a scenario wherein an AI system merges legitimate user commands with malicious instructions retrieved from external web pages to fulfill an attacker's objective. Extending this methodology, researchers targeted authenticated Amazon user accounts. By instructing Atlas to process another malicious newsletter sign-up page, the hidden instructions compelled the browser to inject a new delivery address into the user's logged-in Amazon profile and insert a tablet into the electronic shopping cart.

When guardrails prevented Atlas from finalizing the checkout directly, researchers instructed Atlas to interact with Amazon's native Rufus AI shopping assistant to place the order. Rufus executed the purchase command under the assumption that it was fulfilling a genuine user request. The researchers noted that Rufus itself was not compromised, but simply complied with requests it interpreted as originating from the account owner. Amazon did not respond to requests for comment.

Remediation Efforts and Future Security Imperatives

Zenity disclosed these security findings to OpenAI in January. Addressing the report, an OpenAI spokesperson stated, "Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9." The spokesperson added that these security enhancements extend to the browsing capabilities within the current ChatGPT application, noting that OpenAI continues active research into prompt-injection defense mechanisms.

While real-world cybercriminals frequently rely on simpler exploitation techniques—such as direct phishing campaigns or credential stuffing—Zenity researchers stress that AI architecture must rely on strict, deterministic security boundaries rather than probabilistic AI classification logic. Warning of the broader risks, Bargury remarked, "You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised." He stressed the critical importance of carefully structuring the specific access levels and agency granted to autonomous browsing tools.

Questions & Answers

What security vulnerabilities were identified in AI web browsers?
Researchers uncovered around 20 vulnerabilities that enable unauthorized access to local files, password managers, and browsing history.
How was WhatsApp spam executed through the Atlas browser?
By instructing Atlas to process a malicious page, hidden instructions forced the AI to access WhatsApp Web and message all stored contacts automatically.
How did the security flaw affect Amazon accounts?
Malicious prompts compelled Atlas to add a delivery address, insert products into an Amazon cart, and direct the Rufus AI assistant to complete the interaction.
What was OpenAI's response to the reported findings?
An OpenAI spokesperson stated that updates were deployed to address the issues, and that Atlas is scheduled for deprecation on August 9.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR