
Zenity researchers have uncovered more than a dozen vulnerabilities in AI-powered browsers like OpenAI's Atlas, enabling attackers to spam WhatsApp contacts and trigger unauthorized purchases. Learn how these attacks work and how to protect yourself.
The AI-powered browser is meant to be your ultimate digital assistant, summarizing emails, managing schedules, and even completing purchases with a simple voice command. The promise of AI-native browsing is undeniable. Yet as more users hand over control of their digital lives, cybercriminals are close behind. Security researchers at Zenity have uncovered more than a dozen vulnerabilities in AI-powered browsers, including OpenAI’s Atlas. The flaws open the door to a troubling scenario: an attacker hijacks your AI browser and uses it to spam your WhatsApp contacts or silently place orders on your Amazon account. Here is what the research reveals about the hidden risks of AI-powered browsing.
Web browsers have always been a prime target for attackers. Clicking a malicious link, downloading a contaminated file, or falling victim to a phishing page are well-known risks. AI browsers, however, introduce a new and far more dangerous category of threats. They don’t simply load web pages; they take action. They hold your credentials, connect to your messaging apps, access your email, and understand your context. This level of access makes them attractive targets.
Zenity’s analysis focused on how AI agents interact with third-party services. The researchers found that attackers could exploit the browser’s capabilities to issue commands that it then executes—without the user’s knowledge. A browser with your WhatsApp session is no longer just a communication tool. In the hands of an attacker, it becomes a spamming machine that abuses your identity.
The Zenity research, reported via Wired in 2025, serves as one of the first comprehensive looks at the security posture of the new generation of AI-powered browsers.
The phrase “more than a dozen” may sound modest, but when applied to a nascent technology category, it signals a systemic problem. Zenity’s researchers identified vulnerabilities that range from authorization failures to inadequate safeguards on AI-driven actions.
The vulnerabilities are not unique to a single product. The researchers found that AI browsers share common architectural decisions—specifically, granting agents elevated permissions to handle a wide range of tasks. This design enables the browser to be helpful, but it also ensures that a single successful exploit can have broad consequences.
The most compelling demonstration of the problem came from Zenity’s proof-of-concept attack against OpenAI’s Atlas. The researchers successfully manipulated the AI browser into performing an unauthorized Amazon purchase. The action was completed seamlessly, with the browser believing it was executing a legitimate request.
This PoC illustrates several important facts:
A user who sees their AI browser as a helpful shopping assistant might not realize that the same capability can be redirected toward fraudulent orders, shipping changes, or data theft.
Why are these browsers so exposed? The answer lies in the tension between functionality and security. AI browsers are designed to act, and acting requires authority. They must access emails to draft responses, tap into calendars to schedule meetings, and connect to messaging services to send messages.
The problem is that this broad access is granted without adequate security guardrails to distinguish between legitimate and malicious actions.
An attacker can exploit vulnerabilities in AI browsers through multiple vectors:
Once one of these vectors succeeds, the attacker effectively gains control of the AI agent’s decision-making. The browser’s broad permissions do the rest.
Among the most concerning scenarios is an attack on WhatsApp. The Zenity research highlighted the ability of an attacker to use the AI browser to message a user’s WhatsApp contacts without their knowledge.
The consequences are severe:
WhatsApp is not the only target. Other connected services—email clients, social media platforms, and payment systems—are equally exposed.
It is tempting to think that AI browsers are a consumer concern. But enterprise users are adopting them too. Employees use AI browser assistants to handle customer queries, draft reports, and manage internal communications. A hijacked AI browser in a corporate environment can have devastating consequences.
Attackers could:
For security teams, this new wave of AI-powered tools is a reminder that traditional browser security is no longer sufficient. Securing the browser used to be about training and blocking malicious domains. With AI agents, it is about monitoring intent, behavior, and outcomes.
Zenity’s findings align with a broader trend. From 2024 to 2025, research on AI agent vulnerabilities has grown significantly. The security community is beginning to understand that autonomous agents create an entirely novel attack surface—one that cannot be defended with old playbooks.
The rise of browser-based AI attacks also coincides with the expansion of consumer AI products. OpenAI’s Atlas is not a marginal experiment. It is a polished product designed for mainstream adoption. If such products ship with systemic security weaknesses, millions of users are at risk.
While the research highlights vendor shortcomings, users and organizations can take immediate steps to reduce exposure.
The vulnerabilities identified by Zenity must be treated as a challenge for the whole industry. AI browsers are not inherently dangerous. They become risky when security is treated as an afterthought.
Vendors should adopt a secure-by-design approach:
Until these measures become the standard, users should approach AI browsers with cautious optimism. The productivity gains are real. But so are the risks.
The Zenity research is a sobering reminder that every leap in technology creates new attack surface. OpenAI’s Atlas, WhatsApp, Amazon—the very tools designed to simplify your digital life—can be turned against you through AI browser vulnerabilities. The more than a dozen flaws identified by security researchers demonstrate that the battle for AI security is just beginning.
To stay protected, adopt a least-privilege approach to AI browsing. Review permissions, require confirmations, and keep your software updated. For organizations, the mandate is clear: scrutinize AI tools before deployment and monitor them continuously.
AI browsers are the future of the web. Let us make sure that future is secure.
An AI-powered browser is a web browser that uses artificial intelligence agents to perform tasks automatically, such as summarizing content, managing emails, and making purchases. Unlike traditional browsers that just display web pages, AI browsers can access credentials and third-party services like messaging apps, which makes them more convenient but also more vulnerable to hijacking.
Attackers exploit security flaws in the browser's authorization and action safeguards, tricking the AI agent into executing commands. Once hijacked, the browser can use a logged-in WhatsApp session to send spam messages to your contacts without your knowledge. Zenity researchers found more than a dozen such vulnerabilities in AI browsers like OpenAI's Atlas.
To protect yourself, limit the permissions you grant to AI browsers, especially access to messaging apps and financial accounts. Regularly review connected third-party services, log out when not in use, and keep the browser updated with security patches. Also be cautious about clicking links or granting new permissions, as social engineering can trigger the hijacking.
No, the vulnerabilities were found across multiple AI-powered browsers, not just OpenAI's Atlas. Zenity researchers reported common architectural weaknesses, particularly in how these browsers grant agents excessive permissions and fail to safeguard AI-driven actions. The issue seems systemic to the new generation of AI browsers.
If you suspect your AI browser has been compromised, immediately revoke its access to messaging apps, email, and shopping accounts. Log out of all sessions, change your passwords, and run a security scan on your device. Then check your WhatsApp for any unauthorized messages sent to contacts and review recent orders on connected platforms for unauthorized purchases.