Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity disclosed two AI browser attack chains against ChatGPT Atlas and the Claude in Chrome extension, showing how indirect prompt injection can enable phishing, account takeovers, and unauthorized Amazon purchases. The research highlights how agentic browsers can be manipulated across authenticated sessions, with reports shared to OpenAI and Anthropic. #ChatGPTAtlas #ClaudeinChrome #OpenAI #Anthropic #WhatsAppWeb #Amazon #Rufus

Keypoints

  • Zenity found a zero-click indirect prompt injection issue in ChatGPT Atlas.
  • A planted X comment could redirect Atlas to a malicious payload page.
  • The attack could make Atlas send phishing messages through WhatsApp Web.
  • Zenity also showed account takeover chains against the Claude in Chrome extension.
  • The Claude attack could steal Gmail data, share Google Drive files, and hijack Slack and X accounts.

Read More: https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/