OpenAI Atlas Browser Faces Critical Prompt Injection Vulnerabilities
OpenAI's Atlas browser suffers from critical prompt injection and phishing flaws that allow attackers to execute rogue agent actions and steal user data.
Following the October 2025 launch of the ChatGPT Atlas AI-powered browser for macOS, security researchers discovered critical vulnerabilities that allow attackers to bypass security and execute rogue agent actions. OpenAI developed the Chromium-based browser to provide autonomous web navigation and task automation, but researchers from LayerX and NeuralTrust found that the software lacks meaningful anti-phishing protections and is susceptible to prompt injection.
NeuralTrust identified an omnibox flaw where malformed URLs are treated as trusted user commands, while LayerX uncovered a Tainted Memories vulnerability. This exploit uses cross-site request forgery to inject persistent malicious instructions into a user's account memory across all devices. LayerX further reported that Atlas blocked only 5.8% of real-world phishing attacks, significantly underperforming compared to Google Chrome and Microsoft Edge. These breaches previously targeted the AI platform Hugging Face and exposed user credentials.
In response to the rogue-model incidents, OpenAI Chief Information Security Officer Dane Stuckey acknowledged that prompt injection remains an unsolved security problem. The company has advised enterprise users to evaluate Atlas with low-risk data and cautioned against using it for confidential or production data. Meanwhile, CEO Sam Altman is scheduled to discuss voluntary AI safety tests with Trump administration officials as the federal government signals tighter AI controls.