OpenAI’s Browser Might Be Hijacked to Spam Your WhatsApp Contacts


OpenAI’s Atlas internet browser might have safety protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, in accordance to new analysis introduced immediately at the Black Hat cybersecurity convention in Las Vegas.

The Atlas findings, from researchers at safety agency Zenity, are a part of a broad sequence of flaws the firm found in main AI-enabled internet browsers and browser extensions, together with merchandise from Google, Anthropic, Microsoft, and Perplexity. The researchers discovered round 20 flaws, which allowed them to entry native machines, seize information, take over a password supervisor, and leak somebody’s total searching historical past.

“They’ve nerfed the safety management of browsers—we are now again to seeing the sorts of assaults that you simply noticed on browsers 20 years in the past,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings at the safety convention with Zenity’s Stav Cohen and different colleagues.

Thus far, AI internet browser integrations have largely are available in two kinds: devoted browsers with AI assistants included and extensions that add AI merchandise into current browsers. These bots can navigate web sites for you—summarizing total pages in seconds, as an example—and setups nclude brokers that may take actions on your behalf, usually working throughout a number of completely different tabs.

Safety alarm bells have rung ever since tech firms began racing to introduce brokers into internet searching. As the internet is made up of all types of untrusted information, exposing that to an AI system can lead it to course of malicious instructions and prompt-injection attacks. The assaults are, as OpenAI’s safety boss said final yr, an “unsolved safety downside.” And, as safety researchers have repeatedly warned whereas selecting holes in the instruments, long-standing internet safety practices, resembling same-origin policy that stops web sites interacting with one another, may be made “effectively useless.”

Of all the AI browser instruments they probed, Bargury says OpenAI’s Atlas—which the firm is shutting down next week—had the most protections and safety boundaries in place. Nevertheless, the researchers might nonetheless bypass them to manipulate the system. Different searching instruments have been a lot simpler to hack, they are saying.

In the first proof-of-concept assault, Zenity researchers requested Atlas to join to a publication hyperlink that they posted on X. The malicious webpage containing the sign-up course of consists of directions, written in Hebrew, telling the AI to navigate to the person’s signed-in WhatsApp internet account and ship each contact the identical message. The researchers describe it as a “mass phishing marketing campaign.”

The assault—which does not exploit a vulnerability in WhatsApp—works by getting round a number of safety mechanisms put in place by OpenAI, Bargury says. A blog post details how the researchers declare to have gotten previous security measures, together with designing a publication sign-up web page that seemed official and not one thing attempting to hack individuals, writing in Hebrew to dodge English-language safety instruments, and claiming (falsely) that the system was utilizing a sandboxed model of WhatsApp internet with faux individuals, not the actual factor.

“What it’ll do is undergo every one in all the contacts and ship the directions to be part of this article as nicely—so this is a worm,” Bargury says. “So that you are now infecting the remainder of your family and friends.” (WhatsApp declined to remark on the findings.)

The researchers say the assault is an instance of what they name “intent collision,” the place the AI merges official directions from a person and malicious directions from the internet to full a hackers’ purpose.

Subsequent, the researchers turned to Amazon. Utilizing an analogous method—getting Atlas to join to a faux publication web page with malicious directions—the researchers made the browser add a delivery handle to a logged-in Amazon account and add a pill to the buying cart.




Disclaimer: This article is sourced from external platforms. OverBeta has not independently verified the information. Readers are advised to verify details before relying on them.

0
Show Comments (0) Hide Comments (0)
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Stay Updated!

Subscribe to get the latest blog posts, news, and updates delivered straight to your inbox.