Noma Security demonstrated that an indirect prompt injection could cause OpenAI's ChatGPT Atlas agentic browser to access sensitive email data and place it into an attacker-controlled shared cloud document without requesting user confirmation. The proof of concept used malicious instructions embedded in legitimate-looking content that Atlas autonomously encountered after opening a link; cloud-drive autosave and version history made the resulting disclosure persistent and difficult to undo.
The finding illustrates the agentic-AI risks identified by OWASP's Agentic Security Initiative, whose threat-model-based guidance addresses the expanded autonomy, scale, and security exposure created by LLM-enabled agents. The exposure is not limited to Google Workspace and can affect any shared-cloud workflow an agent can access with sufficient permissions; organizations should enforce least privilege, sandbox agent browsing, threat-model agent tool actions, and monitor agent access to sensitive data and external destinations.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Multiple research teams demonstrated proof-of-concept exploits against ChatGPT Atlas using embedded instructions and hidden text, as reported by The Register.
OpenAI's CISO publicly acknowledged prompt injection as a known and actively monitored attack category. The article states that OpenAI treats newly demonstrated indirect-prompt-injection paths as instances of an established risk class rather than unique vulnerabilities.
Noma Security demonstrated an indirect prompt-injection proof of concept in which ChatGPT Atlas opened a malicious shared cloud document, retrieved the three latest email subjects, and entered them into the attacker-controlled document without a user-confirmation prompt. Autosave and version history could preserve the exposed data, and the technique could apply to other agent-accessible cloud-drive content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.