August 7, 2026

Innovative Wizards

Innovate, Review, Inspire

Cybersecurity Experts Warn AI Browser Agents Could Be Hijacked to Spam WhatsApp Contacts and Steal Sensitive Data

Unwanted promotional and marketing messages on WhatsApp have become a common problem for millions of users. Although WhatsApp continues to introduce new security features to reduce spam, cybersecurity experts have now raised concerns about a new AI-related threat. According to researchers, cybercriminals could hijack AI Browser Agents to automatically send spam or phishing messages to a user’s WhatsApp contacts.

The warning comes from a new study by cybersecurity firm Zenity, which was presented on August 5 at the Black Hat 2026 cybersecurity conference in Las Vegas, United States. Researchers demonstrated that OpenAI’s Atlas AI Browser Agent could be manipulated to send phishing messages to multiple contacts through WhatsApp Web. Importantly, the experiment did not exploit any vulnerability in WhatsApp or compromise its end-to-end encryption.

How Were WhatsApp Messages Sent Through an AI Browser Agent?

According to the researchers, the attack targeted the AI Browser Agent rather than WhatsApp itself. Since the AI agent had access to the user’s browser session, it became the entry point for the attack.

The researchers embedded hidden prompts inside a webpage. Once Atlas opened the page, it accessed the user’s logged-in WhatsApp Web account and automatically sent the same phishing message to everyone in the contact list.

The demonstration showed that if an AI Browser Agent is compromised, it could launch large-scale phishing or spam campaigns without the user’s knowledge.

More Than 20 Security Vulnerabilities Discovered

During the research, the team identified more than 20 security flaws affecting AI Browser Agents and browser extensions developed by companies including OpenAI, Google, Microsoft, Anthropic, and Perplexity.

According to the researchers, attackers could potentially use these weaknesses to:

  • Access files stored on a user’s computer.
  • Take control of password managers.
  • Download sensitive information.
  • Perform unauthorized actions on online shopping platforms.
  • Hijack browser sessions without the user’s permission.

The findings suggest that AI Browser Agents introduce a new category of cybersecurity risks that traditional browser security mechanisms were not designed to address.

Why Are AI Browser Agents Considered Risky?

AI Browser Agents are designed to browse websites, summarize webpages, complete online forms, and perform various web-based tasks automatically.

However, because these agents constantly interact with web content, they can also interpret hidden malicious instructions embedded inside webpages as legitimate user commands.

Researchers explained that this technique is known as a Prompt Injection Attack, where attackers trick AI systems into executing malicious instructions by disguising them as valid user requests.

Although OpenAI had implemented stronger security protections in Atlas compared to many competing AI Browser tools, researchers were still able to bypass several of its security layers.

How Was Atlas Manipulated?

As part of the demonstration, researchers instructed Atlas to register for a newsletter.

The registration webpage secretly contained hidden instructions directing the AI agent to:

  • Open the user’s logged-in WhatsApp Web account.
  • Access every contact in the contact list.
  • Send the same phishing message to each contact.

To bypass Atlas’ security filters, researchers wrote the malicious prompts in Hebrew, as some of the security systems were primarily focused on detecting threats written in English.

They also combined genuine user instructions with hidden malicious prompts in what researchers described as an “Intent Collision Attack.” In addition, Atlas was falsely led to believe it was operating inside a secure sandbox version of WhatsApp Web, making it more willing to execute the hidden commands.

Researchers Also Tested Atlas on Amazon

The Zenity team also evaluated Atlas on Amazon.

They instructed the AI Browser Agent to add a new shipping address to an Amazon account and place a tablet in the shopping cart.

Although OpenAI’s built-in safeguards prevented Atlas from completing the purchase, the researchers then asked Amazon’s AI shopping assistant Rufus to finish the transaction.

According to the report, Rufus followed the instructions without requiring any additional compromise, highlighting potential security concerns when multiple AI systems interact with one another.

OpenAI’s Response

Zenity stated that it privately disclosed its findings to OpenAI in January 2026.

OpenAI responded by saying that Prompt Injection Attacks remain an active area of research, and the company has released multiple security updates this year to strengthen Atlas against such threats.

An OpenAI spokesperson also confirmed that Atlas will be discontinued on August 9. Its AI browsing capabilities will instead be integrated into the ChatGPT Desktop App and Chrome Extension, where additional security protections have been implemented.

Why Is OpenAI Shutting Down Atlas?

Last month, OpenAI announced that it would retire Atlas, its first AI-powered web browser. The company is replacing it with more advanced browsing capabilities integrated into the ChatGPT Desktop App and Chrome Extension.

Atlas was introduced in October 2025 during the growing competition among AI-powered browsers. Other products in this space include Perplexity Comet, The Browser Company’s Dia, as well as AI-enhanced versions of Google Chrome and Microsoft Edge.

Despite the industry’s enthusiasm, AI Browser Agents have struggled to achieve widespread adoption. One major reason is their heavy computational requirements and occasional inaccuracies. These systems typically analyze webpages through screenshots processed by AI models before deciding what actions to perform, making them slower and more resource-intensive than traditional browser automation.

Conclusion

Zenity’s research highlights that while AI Browser Agents have the potential to simplify everyday web browsing, they could also become powerful tools for cybercriminals if adequate security measures are not implemented. Experts believe that AI-powered protection alone is not enough. Future AI Browser Agents will require stronger rule-based security controls and additional safeguards to defend against prompt injection attacks and unauthorized browser activities.

Leave a Reply