OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

58 minutes ago 1

OpenAI’s Atlas web browser could person information protections bypassed and beryllium tricked into spamming dozens of WhatsApp contacts oregon making unauthorized purchases connected Amazon, according to caller probe presented contiguous astatine the Black Hat cybersecurity league successful Las Vegas.

The Atlas findings, from researchers astatine information steadfast Zenity, are portion of a wide bid of flaws the institution discovered successful starring AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. The researchers recovered astir 20 flaws, which allowed them to entree section machines, drawback files, instrumentality implicit a password manager, and leak someone’s full browsing history.

“They person nerfed the information power of browsers—we are present backmost to seeing the kinds of attacks that you saw connected browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings astatine the information league with Zenity’s Stav Cohen and different colleagues.

So far, AI web browser integrations person mostly travel successful 2 forms: dedicated browsers with AI assistants included and extensions that adhd AI products into existing browsers. These bots tin navigate websites for you—summarizing full pages successful seconds, for instance—and setups nclude agents that tin instrumentality actions connected your behalf, often moving crossed aggregate antithetic tabs.

Security alarm bells person rung ever since tech companies started racing to present agents into web browsing. As the web is made up of each sorts of untrusted data, exposing that to an AI strategy tin pb it to process malicious instructions and prompt-injection attacks. The attacks are, arsenic OpenAI’s information brag said past year, an “unsolved information problem.” And, arsenic information researchers person repeatedly warned portion picking holes successful the tools, long-standing web information practices, specified arsenic same-origin argumentation that stops websites interacting with each other, tin beryllium made “effectively useless.”

Of each the AI browser tools they probed, Bargury says OpenAI’s Atlas—which the institution is shutting down adjacent week—had the astir protections and information boundaries successful place. However, the researchers could inactive bypass them to manipulate the system. Other browsing tools were overmuch easier to hack, they say.

In the archetypal proof-of-concept attack, Zenity researchers asked Atlas to motion up to a newsletter nexus that they posted connected X. The malicious webpage containing the sign-up process includes instructions, written successful Hebrew, telling the AI to navigate to the user’s signed-in WhatsApp web relationship and nonstop each interaction the aforesaid message. The researchers picture it arsenic a “mass phishing campaign.”

The attack—which does not exploit a vulnerability successful WhatsApp—works by getting astir aggregate information mechanisms enactment successful spot by OpenAI, Bargury says. A blog station details however the researchers assertion to person got past information measures, including designing a newsletter sign-up leafage that looked morganatic and not thing trying to hack people, penning successful Hebrew to dodge English-language information tools, and claiming (falsely) that the strategy was utilizing a sandboxed mentation of WhatsApp web with fake people, not the existent thing.

“What it’ll bash is spell done each and each 1 of the contacts and nonstop the instructions to articulation this newsletter arsenic well—so this is simply a worm,” Bargury says. “So you are present infecting the remainder of your friends and family.” (WhatsApp declined to remark connected the findings.)

The researchers accidental the onslaught is an illustration of what they telephone “intent collision,” wherever the AI merges morganatic instructions from a idiosyncratic and malicious instructions from the web to implicit a hackers’ goal.

Next, the researchers turned to Amazon. Using a akin approach—getting Atlas to motion up to a fake newsletter leafage with malicious instructions—the researchers made the browser adhd a shipping code to a logged-in Amazon relationship and adhd a tablet to the buying cart.

Read Entire Article