OpenAI has made some big promises with its new AI browser, Atlas, claiming that by putting ChatGPT at the core of intelligent web search, the product is closer to a ‘true super-assistant’ than anything before.
But despite only being launched days ago, security researchers are already warning against an overreliance on the AI-powered browser, especially for corporates with much to lose from an as yet untried and untested web facing application.
First came the general warnings, from the likes of Check Point’s chief technologist Oded Vanunu, who wrote in a research note the day after Atlas’s launch that powerful AI-first browsers introduce new attack vectors like indirect prompt injection, malicious instructions hidden in webpages, that can hijack an AI assistant.
“Browsers are already among the most exploited attack surfaces in computing,” warned Vanunu. “Now add AI that operates with your full privileges across all logged-in sessions banking, email, healthcare, and the corporate system, and the attack surface expands dramatically.”
Couple that with a new report from privacy heavy browser Brave, which found that indirect prompt injection is an issue across the entire category of AI-powered browsers, meaning that agentic browsing like that trumped by OpenAI is ‘’inherently dangerous’.
While those are general problems with AI-browers like Atlas, it is far from the end of the problems for the latest browser on the block. Swiftly following the release of Atlas, security researchers wasted no time in seeing how far they could push OpenAI’s product, with some quickly finding pressure points.
Researchers at Square X, for instance, dug around inside Atlas’s AI sidebar, a prominent feature promoted by OpenAI on the browser’s release, and found a worrying flaw where attackers can use malicious extensions to impersonate the AI sidebar, ‘tricking users to navigate to malicious websites.’
Although initially tested on Comet’s AI sidebar, the Square X team immediately set about the Atlas browser and discovered that both were susceptible to sidebar spoofing attacks, which they claim could allow hackers to run data exfiltration commands and even install backdoors allowing persistent remote access to victims’ machines.
Meanwhile, another team at NeuralTrust published their own findings on Friday (just three days after Atlas hit the shelves) that warned OpenAI’s browser baby was vulnerable to prompt injection attacks aimed at its omnibox – the combined search and address bar that, again, was a main feature of the launch.
Recommended reading
- Perplexity AI Makes $34.5bn Bid for Google Chrome
- CMA Challenges Apple and Google Over Browser Restrictions
- Report: Only 2.8% of Websites Protected Against AI Bots
Here, researchers found that malicious instructions could be disguised to look like a URL, but once this string fails URL validation, Atlas treats the entire content as a prompt. NeuralTrust said that because the browser lacks boundaries between user intent and untrusted content, Atlas interprets this as ‘high-trust’ user intent.
Writing to X, OpenAI’s CISO, Dane Stuckey, acknowledged that the risks in using Atlas, especially in regard to emerging prompt injection techniques, saying that ‘our adversaries will spend significant time and resources to find ways to make ChatGPT agent fall for these attacks’.
However, the firm is working to ensure that the browser is fortified, and will continue to ‘invest heavily in security, privacy, and safety’.





