Researchers and vendors have disclosed serious security weaknesses in AI-enabled browsers, warning that agentic features can undermine core browser protections such as the same-origin policy, tab isolation, and safe handling of cross-origin content. A study cited by Live Science found inconsistent security behavior across seven AI browsers and concluded that more capable products often introduced greater risk, including exposure through prompt injection, multi-tab visibility, and unsafe memory handling. Brave separately detailed indirect prompt injection risks in its discussion of Perplexity Comet, highlighting how malicious web content can manipulate browser agents through embedded instructions.
A separate vulnerability chain in OpenAI’s ChatGPT Atlas browser showed how these design risks can translate into account-compromise scenarios. According to Hacktron AI, exposed Chromium Mojo IPC interfaces were reachable from broadly allowlisted OpenAI web origins, and researchers chained a postMessage-based XSS on forums.openai.com with a login CSRF flaw to execute JavaScript on an authenticated OpenAI domain. From there, they were able to control Atlas browser functions, enumerate and manipulate tabs, and continuously read live tab URLs, enabling theft of OAuth authorization codes that could lead to takeover of accounts such as GitHub, Reddit, and Facebook. OpenAI said it fixed the issue in Atlas version 1.2025.288.15 and awarded a $5,000 bounty.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that several AI-enabled browsers weaken or bypass traditional browser isolation controls, based on testing of seven browsers and analysis of risks including prompt injection, cross-origin access, multi-tab visibility, and memory handling.
The researchers said the Atlas issue was marked resolved on October 28, 2025, and that they received a $5,000 bug bounty for the report.
The Hacktron report states OpenAI deployed a fix for the Atlas browser issue in version 1.2025.288.15 on the same day it acknowledged the vulnerability.
According to the researchers, OpenAI acknowledged a vulnerability chain in the ChatGPT Atlas browser that exposed privileged Chromium Mojo IPC interfaces and enabled browser control from an OpenAI-controlled origin.
Brave published a security write-up about indirect prompt injection in Perplexity Comet, documenting a browser security issue affecting an agentic browser.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
livescience.com
Open sourcehacktron.ai
Open sourcebrave.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.