Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas

AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas

Posted on August 6, 2026 By CWS

AI security firm Zenity has unveiled significant vulnerabilities in the AI browsers Claude in Chrome and ChatGPT Atlas. These flaws can lead to account takeovers, phishing attacks, and unauthorized transactions. Zenity’s detailed research exposes how these browsers could be manipulated without user interaction.

ChatGPT Atlas: A Vulnerable Agentic Browser

Zenity’s investigation into ChatGPT Atlas has highlighted a critical zero-click vulnerability known as indirect prompt injection (IPI). The issue stems not from traditional software bugs but from the browser’s architectural design. This flaw allows attackers to hijack user requests by exploiting ‘intent collision’ through a simple comment on an X thread.

Agentic browsers like Atlas are designed to operate across multiple tabs simultaneously, which inherently breaks the Same-Origin Policy (SOP). This weakness allows attackers to issue commands across authenticated sessions. Zenity demonstrated scenarios where Atlas could be manipulated to send phishing messages via WhatsApp or alter Amazon orders, bypassing certain restrictions.

Claude in Chrome: Elevated Risks

In addition to ChatGPT Atlas, Zenity identified vulnerabilities in the Claude Chrome extension. Here, attackers can escalate indirect prompt injections into complete account takeovers. By sending emails with hidden instructions, Claude can be tricked into executing malicious commands.

These attacks exploit the browser’s high-level permissions to access sensitive data. Zenity illustrated how Claude could be misled into extracting Gmail content or sharing Google Drive files without user consent. These vulnerabilities were reported to Anthropic, but due to their design nature, immediate fixes are challenging.

Implications and Future Outlook

These findings underscore the risks associated with the current design of agentic browsers. While Zenity has shared its discoveries with OpenAI and Anthropic, addressing these vulnerabilities requires rethinking core browser functionalities. As AI technologies continue to evolve, ensuring security remains paramount to protect users from potential cyber threats.

The revelations by Zenity highlight a need for ongoing vigilance and cooperation in the cybersecurity community to mitigate such risks. Users and developers alike must remain informed and proactive in adapting to these evolving threats to safeguard personal and organizational data.

Security Week News Tags:AI security, Anthropic, browser hacking, ChatGPT Atlas, Claude, Cybersecurity, OpenAI, prompt injection, Zenity, zero-click attack

Post navigation

Previous Post: Over 4,400 Rockwell Controllers Vulnerable Online
Next Post: Critical Jenkins Flaw Enables Malicious Code Execution

Related Posts

PromptLock Only PoC, but AI-Powered Ransomware Is Real PromptLock Only PoC, but AI-Powered Ransomware Is Real Security Week News
High-Severity Flaws Patched in Chrome, Firefox High-Severity Flaws Patched in Chrome, Firefox Security Week News
Cyera Raises 0 Million to Expand AI-Powered Data Security Platform Cyera Raises $540 Million to Expand AI-Powered Data Security Platform Security Week News
Quantum Bridge Secures M for Quantum-Safe Cybersecurity Quantum Bridge Secures $8M for Quantum-Safe Cybersecurity Security Week News
Chrome Zero-Day Exploitation Linked to Hacking Team Spyware Chrome Zero-Day Exploitation Linked to Hacking Team Spyware Security Week News
Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark