A security research firm called Zenity spent months trying to break the new wave of AI browsers, the tools that let a chatbot click buttons, fill in forms, and shop on your behalf instead of you doing it yourself. At the Black Hat security conference in Las Vegas, they showed it was easier than most people would like to believe.
The team found around 20 separate flaws across browsers and browser add-ons from OpenAI, Google, Anthropic, Microsoft, and Perplexity. The flaws let an attacker reach into a user's own computer, steal saved files, take over a password manager, or read someone's entire browsing history, all without the person clicking anything suspicious.
The clearest demo involved OpenAI's Atlas browser. Researchers set up a normal-looking newsletter sign-up page and hid instructions inside it, written in Hebrew so English-based safety filters would miss them. Atlas visited the page, picked up the hidden instructions, opened the user's WhatsApp Web session, and sent the same message to every contact in the account. The researchers called it a worm, because each person who got the message could, if they had the same setup, spread it further.
A second demo targeted Amazon. Atlas added a shipping address and a tablet to a logged-in account's cart. When it could not get past OpenAI's checkout protections to finish the purchase, the researchers found a simpler route: they just asked Amazon's own shopping assistant, Rufus, to buy the item, and it complied.
Here is the detail that matters most for anyone running a business. OpenAI's browser had the strongest protections of every product tested, and researchers still got around them. Google, Anthropic, Microsoft, and Perplexity's tools were described as easier to trick. So switching vendors will not solve this. The weakness sits in the basic design of letting a chatbot act on your behalf across the open web, where anyone can plant hidden text on a page.
There is a strange timing twist here too. OpenAI is shutting down Atlas on August 9, less than a year after launching it in October, folding its features into the ChatGPT app and a Chrome extension instead. OpenAI says the shutdown is about low usage and product direction, not this research. But it means the safest AI browser tested just became irrelevant, while the same agent features are moving into products people already use every day.
Before this shutdown was even announced, one enterprise security firm found that close to a quarter of companies already had employees using Atlas at work. That is the real exposure. These tools are already sitting inside company accounts, connected to email, shopping, and messaging, well before the security around them has caught up.
The fix Zenity recommends is blunt: stop relying on the AI's own judgment to decide what is safe, and instead put hard limits on what it is allowed to do without a human confirming first, especially anything involving money or messages sent to other people. Until vendors build that in by default, treat any AI browser feature the same way you would treat handing a new, untested employee your login and your credit card at the same time.