Security researchers at NeuralTrust have discovered a prompt injection vulnerability in the OpenAI Atlas web browser, specifically targeting its omnibox feature. By crafting a string that appears to be a legitimate URL but is intentionally malformed, attackers can embed natural-language instructions that Atlas interprets as trusted user intent. When a user copies and pastes such a string into the omnibox, the browser fails URL validation and instead processes the entire input as a prompt, allowing the embedded instructions to be executed with elevated trust. This exploit leverages the lack of strict separation between trusted user input and untrusted content in the omnibox, making it possible for attackers to perform harmful actions through social engineering.
The attack scenario involves tricking users into copying what looks like a harmless URL, which could be distributed via "Copy link" buttons or similar mechanisms. Once pasted into Atlas, the browser could be directed to visit attacker-controlled websites or even execute more dangerous commands, such as deleting files from connected cloud services. The vulnerability highlights the risks associated with agentic browsers that blend natural-language processing with traditional web navigation, underscoring the need for stricter input validation and clearer boundaries between commands and URLs.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage reported that the Atlas browser exploit could go beyond command execution and be used to manipulate or hijack ChatGPT's memory, expanding the understood impact of the vulnerability. This represented an escalation in the technical details and potential consequences of the attack.
Multiple reports describe a newly disclosed technique that tricks OpenAI's Atlas/ChatGPT browser through crafted or fake URLs in the address bar, causing the system to interpret hidden text as instructions. The issue was presented as a prompt-injection weakness that could lead Atlas to execute unintended commands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.