Multiple vulnerabilities found in OpenAI's Atlas AI browser enable unauthorized Amazon purchase
Security researchers at Zenity have identified more than a dozen vulnerabilities in emerging AI‑driven web browsers, a class of applications that integrate large language models to navigate and interact with web content on behalf of users. The team demonstrated the severity of the flaws by exploiting OpenAI’s Atlas model, prompting it to complete an unauthorized purchase on Amazon without the shopper’s consent. The researchers reported that the vulnerabilities span authentication bypass, command injection, and insufficient sandboxing, allowing malicious actors to manipulate browsing sessions, extract personal data, and trigger transactions through voice or text prompts.
OpenAI has acknowledged the incident and said it is working with Zenity to address the identified issues. The company confirmed that Atlas’s safeguards failed to block the purchase request and that patches are being deployed to strengthen input validation and transaction authorization mechanisms. The findings highlight growing security challenges as AI assistants become more integrated into everyday browsing, prompting calls for stricter testing standards and industry‑wide best practices to protect users from similar exploits.