3 weeks ago

Researchers show hackers could use AI agents to spam WhatsApp

Researchers show hackers could use AI agents to spam WhatsApp
Could hackers use AI agents to spam your WhatsApp contacts? Here’s what researchers found · indianexpress.com

Some tech companies make special web browsers that have a robot helper inside, called an AI agent.

This helper can do things for you, like reading web pages or signing up for newsletters.

Some scientists found that bad people could trick these robot helpers.

They trick them by hiding secret instructions inside normal-looking web pages.

In their test, the helpers sent a message to every person in a person's chat list, like a chain letter.

This is called spam, and it can happen on WhatsApp.

The scientists found more than 20 problems in robot helpers made by five big companies.

They showed their work at a big security meeting in Las Vegas.

The company that made the helper said they are fixing the problem and stopping that browser.

It is important that robots we use on the internet stay safe and only do what we ask.

Key facts

Researchers
Zenity, a cybersecurity firm
Security flaws found
More than 20 in AI-enabled browsers and extensions
Affected companies
OpenAI, Google, Anthropic, Microsoft, Perplexity
Findings presented
Black Hat conference, Las Vegas, August 5
Attack method
Prompt injection via an 'intent collision'; malicious instructions written in Hebrew to bypass English-only safety tools
WhatsApp impact
No WhatsApp vulnerability; end-to-end encryption not compromised
Atlas launch
October 2025
Atlas deprecation
August 9; replaced by a new ChatGPT Chrome extension and updated desktop app

Quotes

Michael Bargury

Co‑founder and CTO of cybersecurity firm Zenity

“You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised, your data can leak. We should be very mindful about planning out what level of access the agents need to get to the browsers and what level of agency they need to use those browsers.”
indianexpress.com
“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.”
indianexpress.com

OpenAI spokesperson

Representative for OpenAI

“Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9. These protections extend to the browser capabilities in the new ChatGPT app.”
indianexpress.com

Sources

Related news