Security vulnerabilities discovered in ChatGPT Atlas browser

October 23, 2025  22:37

Security researchers have identified serious vulnerabilities in OpenAI’s new ChatGPT Atlas browser less than 24 hours after its launch, warning that AI-based browsers pose unprecedented security risks that traditional web protection measures cannot handle, reports Gizmodo.

Immediate vulnerabilities detected

The browser, launched on October 21, 2025, was already compromised by security researchers. Twitter user @elder_plinius demonstrated a “clipboard injection” attack that tricks the Atlas Agent into copying malicious phishing links without the user’s knowledge.

Researchers from Brave Software published detailed findings showing that AI browsers like Atlas are vulnerable to prompt injection attacks, where malicious instructions hidden on websites can manipulate the AI assistant. “When an AI assistant follows malicious instructions from untrusted webpage content, traditional protections such as the same-origin policy or cross-origin resource sharing become completely ineffective,” said Shivan Kaul Sahib, VP of Privacy and Security at Brave.

The vulnerabilities allow attackers to embed commands using methods such as white text on a white background, HTML comments, or nearly invisible text inside images. In demonstrations, researchers showed how hidden instructions in a Reddit comment could make AI browsers navigate to account pages, extract email addresses, access Gmail for authentication codes, and post credentials as comments.

OpenAI acknowledges the risks

OpenAI’s Chief Information Security Officer, Dane Stucki, addressed the security concerns directly, stating that the ChatGPT agent “can still make (sometimes unexpected!) mistakes, such as attempting to purchase the wrong item or failing to consult you before taking important actions.” The company acknowledged that agents are susceptible to “hidden malicious instructions that can be embedded in places such as a webpage or email with the intent to override the intended behavior of the ChatGPT agent.”

According to OpenAI documentation, such attacks “can result in data theft from sites where you are logged in or in actions you did not intend to perform.” The company has implemented protective measures, including restricting agent operations to active browser tabs and requiring user approval for actions on sensitive sites, such as financial institutions.


 
 
 
 
  • Archive