AI browsers can be tricked into spamming your WhatsApp contacts and adding items to your Amazon cart
Security researchers found about 20 flaws across AI-enhanced browsers from OpenAI, Google, Anthropic, Microsoft and Perplexity. The worst let hackers turn your browser into a phishing machine.

Key points
- Security firm Zenity found roughly 20 flaws in AI-enabled browsers and browser extensions from OpenAI, Google, Anthropic, Microsoft and Perplexity, presented at Black Hat Las Vegas in 2025.
- One attack tricked OpenAI's Atlas browser into messaging every WhatsApp contact a user had, effectively turning their account into a spam machine.
- A second attack added a new shipping address and a tablet to a victim's Amazon cart without their knowledge.
- OpenAI patched the Atlas issues in early 2025 and is shutting the browser down on 9 August 2025.
- Researchers warn that AI browsers must use hard, fixed security rules rather than relying on the AI's own judgment, which can almost always be fooled.
Security researchers have shown that AI-powered web browsers, software that uses artificial intelligence to browse websites and take actions on your behalf, can be quietly hijacked to spam your contacts and tamper with your online shopping accounts. The findings were presented this week at Black Hat, a major cybersecurity conference held in Las Vegas.
The research comes from Zenity, a security company that probed AI browser tools built by several of the biggest names in tech. They found around 20 separate weaknesses across products from OpenAI, Google, Anthropic, Microsoft and Perplexity.
What exactly did the attackers do?
The researchers used a technique called a prompt-injection attack, where hidden instructions buried inside a normal-looking webpage tell the AI to do something the user never asked for. Think of it as leaving a note inside a letter that only the AI postman reads.
In the first test, Zenity posted a link on X to what looked like a newsletter sign-up page. Hidden inside that page were instructions written in Hebrew, a deliberate choice to slip past security tools that scan for suspicious English text. The page also claimed, falsely, that the AI was operating inside a safe test environment with fake contacts.
OpenAI's Atlas browser fell for it. It visited the sign-up page, then navigated to the user's already-logged-in WhatsApp Web account and sent the same message to every contact in the list. The researchers call this a worm: each friend who clicked the link would then have their own contacts messaged, and so on.
The second test targeted Amazon. Using the same trick, the researchers got Atlas to add a new shipping address to a logged-in Amazon account and drop a tablet into the shopping cart. When they tried to go further and complete the purchase, OpenAI's safety checks blocked it. So they found a workaround: they asked Amazon's own built-in AI shopping assistant, called Rufus, to finish the order. Rufus, which had not been tampered with, simply assumed it was talking to the real customer and agreed.
Should you worry about your AI browser right now?
If you use Atlas, you have a short window to be aware of this, but OpenAI says it already patched the specific flaws after Zenity reported them in January 2025, and Atlas shuts down completely on 9 August 2025. The company says the protections now also extend to its ChatGPT browser features.
Broader concern is warranted, though. The researchers found similar weaknesses across other AI browser tools from competing companies, some of which were easier to exploit than Atlas.
Real criminals currently have simpler options, such as fake emails or stolen passwords. But Zenity's Michael Bargury argues the industry is sleepwalking into a bigger problem by letting the AI itself decide what is safe, rather than building firm rules the AI cannot override.
| Browser or tool | Company | Key flaw found |
|---|---|---|
| Atlas | OpenAI | WhatsApp spam worm; Amazon cart manipulation |
| Multiple browser extensions | Google, Anthropic, Microsoft | File access, password manager takeover, browsing history leak |
| AI browser integrations | Perplexity | Security bypass allowing machine access |
"You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised, your data can leak," Bargury said, as first reported by Wired AI.
Common questions
Do I need to do anything right now?
If you use Atlas, stop using it before 9 August 2025 when it closes. For other AI browsers and extensions, check whether the company has issued a recent security update, and until one is confirmed, avoid using them while logged into sensitive accounts like your bank, email or messaging apps.
Why can't the AI just refuse the malicious instructions?
That is exactly the problem. AI systems make judgment calls rather than following fixed rules, and clever attackers can fool those judgments, for example by writing in a different language or claiming the environment is a safe test. Researchers argue that hard technical barriers, walls the AI simply cannot cross regardless of what it is told, are the only reliable fix.



