A browser agent that fires off a mass message to every WhatsApp contact is one of roughly 20 attack scenarios Zenity researchers demonstrated at Black Hat this week. The flaws span AI browsers and extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity, and open paths to local files, password managers, and full browsing history.
OpenAI’s Atlas browser carried the most protections of those tested but was still bypassed. In one proof of concept, a fake newsletter signup page with instructions written in Hebrew steered Atlas to a signed-in WhatsApp web account and sent every contact the same message, a technique the researchers call a worm. The attack does not exploit a WhatsApp vulnerability.
In another demonstration, Atlas dropped a shipping address and a tablet into a logged-in Amazon account, then turned to the retailer’s Rufus assistant to finish the checkout. The researchers say Rufus was not hijacked, just asked by what it took to be the customer, and it complied. They call the pattern intent collision, where the AI merges legitimate user instructions with malicious web content.
OpenAI says it deployed an update addressing the issue in January and that protections extend to the new ChatGPT app. Atlas is being deprecated on August 9. Zenity argues for deterministic security barriers instead of AI judgment, which it says can nearly always be fooled.