27 Sources
[1]
OpenAI wants to power your browser, and that might be a security nightmare
The browser wars are heating up again, this time with AI in the driver's seat. OpenAI just launched Atlas, a ChatGPT-powered browser that lets users surf the web using natural language and even includes an "agent mode" that can complete tasks autonomously. It's one of the biggest browser launches
[2]
Are AI browsers worth the security risk? Why experts are worried
Experts warn of rising prompt injection and data theft risks. This year has certainly been the year for artificial intelligence (AI) development. With the sudden launch of OpenAI's ChatGPT, businesses worldwide scrambled to implement the chatbot and its associated applications into their
[3]
Be Careful With AI Browsers: A Malicious Image Could Hack Them
When he's not battling bugs and robots in Helldivers 2, Michael is reporting on AI, satellites, cybersecurity, PCs, and tech policy. Don't miss out on our latest stories. Add PCMag as a preferred source on Google. AI-powered browsers are supposed to be smart. However, new security research
[4]
AI browsers wide open to attack via prompt injection
Agentic features open the door to data exfiltration or worse Feature With great power comes great vulnerability. Several new AI browsers, including OpenAI's Atlas, offer the ability to take actions on the user's behalf, such as opening web pages or even shopping. But these added capabilities
[5]
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts
Cybersecurity researchers have flagged a new security issue in agentic web browsers like OpenAI ChatGPT Atlas that exposes underlying artificial intelligence (AI) models to context poisoning attacks. In the attack devised by AI security company SPLX, a bad actor can set up websites that serve
[6]
Please stop using AI browsers
The emergence of AI-enabled web browsers promise a radical shift in how we navigate the internet, with new browsers like Perplexity's Comet, OpenAI's ChatGPT Atlas, and Opera Neon integrating language models (LLMs) directly into the browsing experience. They promise to be intelligent assistants
[7]
Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
OpenAI's Atlas and Perplexity's Comet browsers are vulnerable to attacks that spoof the built-in AI sidebar and can lead users into following malicious instructions. The AI Sidebar Spoofing attack was devised by researchers at browser security company SquareX and works on the latest versions of
[8]
OpenAI's ChatGPT Atlas is vulnerable to prompt injection attacks within the omnibox
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Facepalm: Prompt injection attacks are emerging as a significant threat to generative AI services and AI-enabled web browsers. Researchers have now uncovered an even more insidious method - one that
[9]
Atlas vuln allows malicious memory injection into ChatGPT
In yet another reminder to be wary of AI browsers, researchers at LayerX uncovered a vulnerability in OpenAI's Atlas that lets attackers inject malicious instructions into ChatGPT's memory using cross-site request forgery. This exploit, dubbed ChatGPT Tainted Memories by browser security vendor
[10]
OpenAI's Atlas browser has a security flaw that could expose your private info
This type of attack can be used to steal login credentials, credit card numbers, and other sensitive data. The company best known for ChatGPT, OpenAI, surprised us earlier this week by dropping its new AI-powered browser, Atlas. And since its debut, it appears to be the talk of the town, as we see
[11]
New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands
Cybersecurity researchers have discovered a new vulnerability in OpenAI's ChatGPT Atlas web browser that could allow malicious actors to inject nefarious instructions into the artificial intelligence (AI)-powered assistant's memory and run arbitrary code. "This exploit can allow attackers to
[12]
ChatGPT Atlas is already facing scams and jailbreaks -- here's how to stay safe while using the AI browser
This major release from OpenAI is the perfect opportunity for hackers and scammers to prey on unsuspecting users ChatGPT Atlas is having a rocky launch to say the least. While the new browser is being praised by many as the next big thing in web browsing, it has already raised big questions over
[13]
When your AI browser becomes your enemy: The Comet security disaster
Remember when browsers were simple? You clicked a link, a page loaded, maybe you filled out a form. Those days feel ancient now that AI browsers like Perplexity's Comet promise to do everything for you -- browse, click, type, think. But here's the plot twist nobody saw coming: That helpful AI
[14]
OpenAI's new Atlas browser may have some extremely concerning security issues, experts warn - here's what we know
Only use agentic browsing when you're not handling sensitive info Just days after OpenAI released Atlas, its take on the web browser, the company is battling to maintain its reputation amid security concerns. The Chromium-based browser which has a built-in AI agent for web navigation and
[15]
Serious New Hack Discovered Against OpenAI's New AI Browser
It didn't take long for cybersecurity researchers to notice some glaring issues with OpenAI's recently unveiled AI browser Atlas. The browser, which puts OpenAI's blockbuster ChatGPT front and center, features an "agent mode" -- currently limited to paying subscribers -- that allows it to complete
[16]
Experts warn OpenAI's ChatGPT Atlas has security vulnerabilities that could turn it against users -- revealing sensitive data, downloading malware, and worse | Fortune
Cybersecurity experts are warning that OpenAI's new browser, ChatGPT Atlas, could be vulnerable to malicious attacks that could turn AI assistants against users, potentially stealing sensitive data or even draining their bank accounts. The AI company launched Atlas on Tuesday, with the goal of
[17]
OpenAI's ChatGPT Atlas Browser Has a Big Problem -- How Crypto Users Can Protect Themselves - Decrypt
OpenAI Chief Security Officer Dane Stuckey admitted the threat "remains an unsolved problem" OpenAI's new ChatGPT Atlas browser, launched Tuesday, is facing backlash from experts who warn that prompt injection attacks remain an unsolved problem despite the company's safeguards. Crypto users need
[18]
ChatGPT's new browser wants to track you around the internet -- here's why that could be a problem
OpenAI, the company behind ChatGPT, is now dipping its toes into a world that it has been interested in for a while now: Web browsing. There have been rumours for months, if not years, that OpenAI would one day release its own AI browser, and now it is here. ChatGPT Atlas is a competitor to the
[19]
SquareX warns of 'AI Sidebar Spoofing' attacks targeting AI browsers - SiliconANGLE
SquareX warns of 'AI Sidebar Spoofing' attacks targeting AI browsers New research out today from browser security company SquareX Ltd. is warning of a new class of browser-based attack known as AI Sidebar Spoofing, which exploits users' trust in artificial intelligence assistants built into modern
[20]
OpenAI's New AI Browser Is Already Falling Victim to Prompt Injection Attacks
OpenAI unveiled its Atlas AI browser this week, and it's already catching heat. Cybersecurity researchers are particularly alarmed by its integrated "agent mode," currently limited to paying subscribers, that can attempt to do online tasks autonomously. Two days after OpenAI unveiled Atlas,
[21]
The ChatGPT Atlas browser is already facing its first security exploit
Its "Memories" feature stores contextual summaries of visited websites by default, alarming privacy experts. OpenAI has launched ChatGPT Atlas, a new web browser that integrates a chatbot interface, a release that has prompted immediate security and privacy concerns from researchers. The browser,
[22]
OpenAI launches ChatGPT-powered web browser. What to know before downloading.
AMD said on October 6 it will supply artificial intelligence chips to OpenAI in a multi-year deal that would bring in tens of billions of dollars in annual revenue and give the ChatGPT creator the option to buy up to roughly 10% of the chipmaker. * OpenAI introduced ChatGPT Atlas, a new internet
[23]
OpenAI's New AI Web Browser Is a Bit of Mess
Earlier this week, OpenAI unveiled an AI browser, dubbed Atlas, which is built around its blockbuster AI product, ChatGPT. "A browser built with ChatGPT takes us closer to a true super-assistant that understands your world and helps you achieve your goals," the company boasted in its
[24]
Perplexity's Comet and Other AI Browsers Could Be Vulnerable to Hacking
Attackers can use various techniques to hide the malicious instructions Perplexity's Comet browser and other artificial intelligence (AI)-powered browsers might be vulnerable to prompt injections, claimed a new study. This study, which was conducted by Brave, claims that they were able to embed
[25]
Researchers Find Severe Vulnerabilities in AI Browser
Go figure that letting an AI control your access to the internet can be a dangerous thing. A hype cycle as overwhelming and logic-defying as the AI boom comes with its own whirlwind succession of trends that are their own mini booms driven by billions of dollars of money. Once the world got used
[26]
How Can Prompt Injections Pit An AI Browser Against You?
On October 21, internet company Brave disclosed significant new vulnerabilities in Perplexity's AI-powered web browser Comet that expose users to "prompt injection" attacks via images and hidden text. According to the company's blog, an attacker can embed faint, nearly invisible instructions
[27]
Hackers can trick ChatGPT Atlas using fake URLs, cybersecurity firm warns
Atlas stores unencrypted OAuth tokens, granting unauthorized access to user accounts. OpenAI has been in the spotlight since introducing the ChatGPT Atlas browser. The company claims that it is specifically designed to incorporate AI-powered assistance directly into web browsing. However, it has
Share
Copy Link
OpenAI's new Atlas browser and other AI-powered browsers are exposing users to serious security risks through prompt injection attacks, data theft, and malicious content manipulation, raising concerns about the safety of autonomous web browsing.
OpenAI has launched Atlas, a ChatGPT-powered browser that promises to revolutionize web browsing through natural language interaction and autonomous task completion. The browser represents one of the most significant browser launches in recent memory, featuring an "agent mode" that can complete tasks independently across the web
1
. However, the debut comes with critical security vulnerabilities that have raised alarm among cybersecurity experts.
Source: Tom's Guide
Atlas integrates ChatGPT with every search query and open tab, using their content and data to answer queries or perform tasks. Early testing has shown promise for applications including online ordering, email editing, conversation summarization, and GitHub repository analysis
2
. The browser maintains ChatGPT memory across sessions, allowing conversations to draw on past chats and details to help users accomplish new tasks.Security researchers have identified serious prompt injection vulnerabilities affecting Atlas and other AI browsers. Brave Software published detailed findings showing how attackers can manipulate AI browsers through both direct and indirect prompt injection attacks
4
. These attacks occur when malicious actors embed hidden commands in web content that AI systems interpret as legitimate instructions.
Source: Futurism
In one demonstration, researchers successfully hid malicious instructions in images using faint light blue text on yellow backgrounds, effectively invisible to users but readable by AI systems
3
. When Perplexity's Comet browser analyzed such images, it executed the hidden commands, including accessing user emails and visiting attacker-controlled websites.The security issues extend beyond individual browsers to represent systemic problems across the AI browser category. Researchers found that Fellou browser could be compromised simply by navigating to malicious websites containing hidden instructions
3
. The browser would read these instructions and execute them, including accessing email inboxes and transmitting sensitive information to external servers.Additional vulnerabilities include cross-site request forgery attacks, where malicious websites can send commands to ChatGPT as if they were the authenticated user
4
. These attacks can persist across devices and sessions by affecting ChatGPT's memory system, creating long-term security compromises.Cybersecurity researchers have identified a new attack vector called "AI-targeted cloaking," where malicious websites serve different content to AI crawlers than to human users
5
. This technique exploits the fact that AI systems treat retrieved content as ground truth, allowing attackers to manipulate what millions of users see as authoritative information through simple user agent detection.
Source: SiliconANGLE
The attack represents a sophisticated evolution of traditional search engine cloaking, optimized specifically for AI crawlers from various providers. By serving manipulated content to AI systems while showing legitimate content to human visitors, attackers can introduce bias, spread misinformation, and undermine trust in AI tools.
Related Stories
OpenAI's Chief Information Security Officer Dane Stuckey acknowledged that prompt injection remains "a frontier, unsolved security problem" and confirmed the company is investing heavily in security measures
2
. Atlas includes optional "logged-out mode" that prevents ChatGPT from accessing user credentials, and "Watch mode" requires users to monitor sensitive operations.However, comprehensive testing by hCaptcha's Threat Analysis Group revealed that browser agents attempted nearly every malicious request without requiring jailbreaking techniques
5
. The study found that when actions were blocked, it typically resulted from missing technical capabilities rather than built-in safeguards.Security experts, including Django co-creator Simon Willison, remain "deeper skeptical" of agentic AI browsers, noting that even basic tasks like summarizing Reddit posts could lead to data exfiltration
2
. The fundamental issue stems from AI browsers operating with users' authenticated privileges, allowing compromised systems to access banking, healthcare, corporate systems, and personal accounts.Brave Software has called for additional safeguards, including explicit user consent for all agentic browsing actions and improved detection systems for malicious content
3
. The company argues that the current security model renders traditional protections like same-origin policy irrelevant when AI assistants execute with full user privileges.Summarized by
Navi
[4]
30 Jun 2026•Technology

30 Oct 2025•Technology

20 Jul 2026•Technology

1
Science and Research

2
Policy and Regulation

3
Technology