
Baaritaan: Biraawsarka Atlas ee OpenAI waxaa loo marin-karo inuu farriimo xayeysiin ah ku diro WhatsApp
Saraakiisha amniga ee Zenity ayaa shaaciyay in biraawsarka Atlas ee OpenAI ay suurtagal tahay in la dhex-maro ammaantiisa oo uu farriimo xayeysiin ah ku diro dadka la xiriirta WhatsApp ama uu wax ku iibsado Amazon. Natiijooyinka waxaa lagu soo bandhigay shirka Black Hat ee Las Vegas.
Dayacaan la helay oo ku baahsan biraawsarro kala duwan
Shirkadda amniga ee Zenity ayaa heshay ilaa 20 dayacaan oo ku saabsan biraawsarrada iyo kordhintooda ay ku shaqeeyaan AI, kuwaas oo ay ka mid yihiin alaabooyin ka yimid Google, Anthropic, Microsoft iyo Perplexity. Dayacaanadan ayaa u oggolaaday baarayaasha inay galaan kombuyuutarrada, faylal qaataan, maamulaha ereyada sirta ah la wareegaan, taariikhda daalacashada daayaan.
Michael Bargury, oo ah aasaasaha iyo CTO-ga Zenity, ayaa sheegay in ammaanta biraawsarka la wiiqay, isagoo ku dooday: 'They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.' Waxa uu natiijadaas la wadaagay Stav Cohen iyo asxaabtiisa.
Weerarrada tusaalaha ah iyo xaddidaadaha OpenAI
Atlas ayaa lahayd ammaanta ugu badan ee la baaray, laakiin baarayaasha ayaa wali ka gudbay oo wax ka beddelay. Weerarkii ugu horreeyay, Atlas waxaa loo sheegay inuu isdiiwaangeliyo warsid, boggii xunna wuxuu ku qoray Cibriish inuu farriimaha u diro xiriirayaasha WhatsApp; weerarkaas loo yaqaan 'mass phishing campaign' oo aan dhibic ka faa'iidayn WhatsApp.
Tusaale kale, Amazon ayay ku dartay cinwaan iyo tablet, laakiin iibsashada tooska ah way ku guuldareysteen. Waxay ku guuleysteen inay Atlas ka dhigaan Rufus inuu iibsado: 'Rufus was not hijacked or injected, it was just asked, by what it took to be the customer, and it complied.' OpenAI ayaa Janaayo la wargelisay, waxyar kadibna cusbooneysiis ay ku xoojisay soo saartay.
Talada amniga iyo mustaqbalka Atlas
OpenAI ayaa xaqiijisay in bixisay cusbooneysiin, iyagoo leh: 'Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9.' Ammasimadaas ayaa sidoo kale dhexaysa awoodda biraawsarka ee abka cusub ee ChatGPT, waxaana ay shirkadu si firfircoon u baaraysaa weerarada prompt-injection.
Bargury wuxuu ka digay in 'browser can completely get hijacked and your accounts can get compromised, your data can leak.' Wuxuu ku taliyay in la isticmaalo xannibaadaha amniga ee 'deterministic', ee aan kaliya ku tiirsanayn go'aamada AI, iyo in la qorsheeyo heerka marin-helidda ay wakiilladu u baahan yihiin.
Security researchers at Zenity have revealed that OpenAI's Atlas web browser can be manipulated to send mass messages to WhatsApp contacts and add items to Amazon shopping carts, findings presented at the Black Hat cybersecurity conference in Las Vegas.
Broad Flaws Discovered in AI-Powered Browsers
Zenity researchers identified approximately 20 security flaws across leading AI-enabled web browsers and extensions, including products from Google, Anthropic, Microsoft, and Perplexity. These vulnerabilities allowed attackers to access local machines, steal files, hijack password managers, and leak entire browsing histories.
OpenAI's Atlas browser had the most robust protections among the tools tested, yet researchers still managed to bypass its security boundaries. Other AI browsing tools were significantly easier to compromise, raising concerns about the safety of AI-integrated web applications.
WhatsApp Spam Attack Demonstrates 'Intent Collision' Risk
In a proof-of-concept attack, researchers tricked Atlas into signing up for a newsletter via a malicious webpage containing Hebrew instructions. The AI was then directed to access the user's WhatsApp account and send identical messages to all contacts, a tactic described as a 'mass phishing campaign.'
The attack exploits 'intent collision,' where the AI merges legitimate user instructions with malicious web directives to achieve a hacker's goal. This does not target WhatsApp directly but circumvents OpenAI's security mechanisms, including using a fake newsletter page and claiming the system uses a sandboxed version of WhatsApp.
Amazon Purchase Attempt and OpenAI's Response
Researchers also attempted to manipulate Atlas to add a shipping address and tablet to a logged-in Amazon account. Unable to bypass OpenAI's safety measures for direct purchases, they instead instructed the browser to ask Amazon's Rufus AI shopping assistant to complete the transaction on the user's behalf.
OpenAI reported the findings in January and deployed an update to strengthen Atlas's protections, with the browser set to be deprecated on August 9. The company emphasized that these security enhancements will also apply to the browser capabilities in the new ChatGPT app.



