AI security firm Zenity has unveiled significant vulnerabilities in the AI browsers Claude in Chrome and ChatGPT Atlas. These flaws can lead to account takeovers, phishing attacks, and unauthorized transactions. Zenity’s detailed research exposes how these browsers could be manipulated without user interaction.
ChatGPT Atlas: A Vulnerable Agentic Browser
Zenity’s investigation into ChatGPT Atlas has highlighted a critical zero-click vulnerability known as indirect prompt injection (IPI). The issue stems not from traditional software bugs but from the browser’s architectural design. This flaw allows attackers to hijack user requests by exploiting ‘intent collision’ through a simple comment on an X thread.
Agentic browsers like Atlas are designed to operate across multiple tabs simultaneously, which inherently breaks the Same-Origin Policy (SOP). This weakness allows attackers to issue commands across authenticated sessions. Zenity demonstrated scenarios where Atlas could be manipulated to send phishing messages via WhatsApp or alter Amazon orders, bypassing certain restrictions.
Claude in Chrome: Elevated Risks
In addition to ChatGPT Atlas, Zenity identified vulnerabilities in the Claude Chrome extension. Here, attackers can escalate indirect prompt injections into complete account takeovers. By sending emails with hidden instructions, Claude can be tricked into executing malicious commands.
These attacks exploit the browser’s high-level permissions to access sensitive data. Zenity illustrated how Claude could be misled into extracting Gmail content or sharing Google Drive files without user consent. These vulnerabilities were reported to Anthropic, but due to their design nature, immediate fixes are challenging.
Implications and Future Outlook
These findings underscore the risks associated with the current design of agentic browsers. While Zenity has shared its discoveries with OpenAI and Anthropic, addressing these vulnerabilities requires rethinking core browser functionalities. As AI technologies continue to evolve, ensuring security remains paramount to protect users from potential cyber threats.
The revelations by Zenity highlight a need for ongoing vigilance and cooperation in the cybersecurity community to mitigate such risks. Users and developers alike must remain informed and proactive in adapting to these evolving threats to safeguard personal and organizational data.
