3 weeks ago
Researchers show hackers could use AI agents to spam WhatsApp
Some tech companies make special web browsers that have a robot helper inside, called an AI agent.
This helper can do things for you, like reading web pages or signing up for newsletters.
Some scientists found that bad people could trick these robot helpers.
They trick them by hiding secret instructions inside normal-looking web pages.
In their test, the helpers sent a message to every person in a person's chat list, like a chain letter.
This is called spam, and it can happen on WhatsApp.
The scientists found more than 20 problems in robot helpers made by five big companies.
They showed their work at a big security meeting in Las Vegas.
The company that made the helper said they are fixing the problem and stopping that browser.
It is important that robots we use on the internet stay safe and only do what we ask.
Cybersecurity firm Zenity found that OpenAI's Atlas browser's built-in AI agent can be tricked into spamming a user's WhatsApp contacts.
The findings were presented on Wednesday, August 5, at the Black Hat cybersecurity conference in Las Vegas.
Researchers identified more than 20 security flaws in AI-enabled browsers and extensions from OpenAI, Google, Anthropic, Microsoft, and Perplexity.
The proof-of-concept phishing attack used hidden malicious instructions, written in Hebrew to bypass English-only safety tools; WhatsApp's end-to-end encryption was not compromised.
OpenAI says it deployed an update to strengthen Atlas protections and will deprecate the browser on August 9, extending protections to the new ChatGPT app and a Chrome extension.
- Who
- Researchers at cybersecurity firm Zenity, including cofounder and CTO Michael Bargury.
- What
- Demonstrated that OpenAI's Atlas AI browser agent can be hijacked via prompt injection to spam a user's WhatsApp contacts, and found more than 20 security flaws in AI browser agents and extensions.
- Where
- Black Hat cybersecurity conference in Las Vegas, Nevada, United States.
- When
- Findings presented on Wednesday, August 5, at the Black Hat conference; researchers reported the findings to OpenAI in January 2026.
- Why
- To highlight the cybersecurity risks of autonomous AI browser agents and the need for new safeguards tailored to them.
Security researchers' concerns
OpenAI's response and industry push
Seriousness of AI agent vulnerabilities
Security researchers' concerns
Zenity researchers say AI browser agents can make long-standing browser security controls 'effectively useless,' warning that browsers can be hijacked, accounts compromised, and data leaked, and they recommend deterministic hard security barriers rather than AI-powered classifiers.
OpenAI's response and industry push
OpenAI says prompt-injection attacks are something it actively researches, that it deployed an update to strengthen protections in Atlas, and that Atlas is being deprecated on August 9 in favor of a new ChatGPT Chrome extension and updated desktop app with extended protections.
Future of AI browser agents
Security researchers' concerns
The research warns that autonomous AI agents in browsers introduce new cybersecurity risks and shows the need for new safeguards specifically tailored to AI browser agents before widespread adoption.
OpenAI's response and industry push
Tech companies continue investing in AI browsers — Google and Microsoft expanded AI capabilities in Chrome and Edge, Perplexity launched Comet, and The Browser Company introduced Dia — though adoption has struggled due to massive computational requirements and potential inaccuracy.
Key facts
- Researchers
- Zenity, a cybersecurity firm
- Security flaws found
- More than 20 in AI-enabled browsers and extensions
- Affected companies
- OpenAI, Google, Anthropic, Microsoft, Perplexity
- Findings presented
- Black Hat conference, Las Vegas, August 5
- Attack method
- Prompt injection via an 'intent collision'; malicious instructions written in Hebrew to bypass English-only safety tools
- WhatsApp impact
- No WhatsApp vulnerability; end-to-end encryption not compromised
- Atlas launch
- October 2025
- Atlas deprecation
- August 9; replaced by a new ChatGPT Chrome extension and updated desktop app
Quotes
Michael Bargury
Co‑founder and CTO of cybersecurity firm Zenity
“You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised, your data can leak. We should be very mindful about planning out what level of access the agents need to get to the browsers and what level of agency they need to use those browsers.”
indianexpress.com
“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.”
indianexpress.com
OpenAI spokesperson
Representative for OpenAI
“Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9. These protections extend to the browser capabilities in the new ChatGPT app.”
indianexpress.com











