Security researchers at Zenity discovered more than a dozen vulnerabilities in OpenAI’s AI‑browser product, Atlas, and proved the flaws could let the browser place unauthorized purchases on Amazon. The study, reported by WIRED, suggests the same weaknesses could be used to hijack Atlas to spam WhatsApp contacts.
According to WIRED, Zenity’s team exploited the bugs to trigger an Amazon transaction without the user’s consent. The researchers highlighted how a hijacked browser could potentially send spam messages through WhatsApp, raising concerns about user data and payment security. No specific quote from OpenAI was provided.
The incident underscores growing worries over the security of emerging AI‑driven browsers, which are increasingly integrated into everyday digital workflows.