What's Happening?
AI security company Zenity has revealed vulnerabilities in AI browsers Claude in Chrome and ChatGPT Atlas, which can be exploited for account takeovers and unauthorized purchases. The vulnerabilities,
reported to Anthropic and OpenAI, involve zero-click indirect prompt injection (IPI) attacks that allow hackers to hijack user sessions and perform actions across authenticated domains. Zenity demonstrated scenarios where attackers could manipulate AI agents to send phishing messages or make unauthorized purchases. Despite the disclosure, the vulnerabilities remain unpatched due to their reliance on the core capabilities of agentic browsers.
Why It's Important?
These findings highlight significant security risks associated with AI browsers, which are increasingly used for various online tasks. The vulnerabilities pose a threat to user privacy and security, as they can lead to unauthorized access to personal accounts and sensitive information. The inability to patch these vulnerabilities underscores the challenges in securing AI technologies and the need for robust security measures. This situation could impact user trust in AI applications and prompt calls for stricter regulations and security standards in the AI industry.
What's Next?
As the vulnerabilities remain unpatched, users of AI browsers like Claude and ChatGPT Atlas should exercise caution and implement additional security measures. Companies like Anthropic and OpenAI may need to explore alternative solutions to address these security issues. The disclosure could lead to increased scrutiny of AI technologies and push for industry-wide security improvements. Stakeholders, including policymakers and tech companies, may engage in discussions to develop guidelines and best practices for securing AI applications.






