Close Menu
    Trending
    • TDS Newsletter: How Compelling Data Stories Lead to Better Business Decisions
    • I Measured Neural Network Training Every 5 Steps for 10,000 Iterations
    • “The success of an AI product depends on how intuitively users can interact with its capabilities”
    • How to Crack Machine Learning System-Design Interviews
    • Music, Lyrics, and Agentic AI: Building a Smart Song Explainer using Python and OpenAI
    • An Anthropic Merger, “Lying,” and a 52-Page Memo
    • Apple’s $1 Billion Bet on Google Gemini to Fix Siri
    • Critical Mistakes Companies Make When Integrating AI/ML into Their Processes
    ProfitlyAI
    • Home
    • Latest News
    • AI Technology
    • Latest AI Innovations
    • AI Tools & Technologies
    • Artificial Intelligence
    ProfitlyAI
    Home » ChatGPT Atlas Is Facing Major Backlash Over Its Security Flaws
    Latest News

    ChatGPT Atlas Is Facing Major Backlash Over Its Security Flaws

    ProfitlyAIBy ProfitlyAIOctober 28, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    OpenAI’s new ChatGPT Atlas browser is rolling out with highly effective agentic options designed to learn pages, click on buttons, and perform duties on a consumer’s behalf.

    However virtually instantly, safety researchers are sounding the alarm, warning that this new agentic shopping mode creates a harmful and extremely exploitable new assault floor.

    To know simply how severe these dangers are and what it means for companies and customers, I talked it via with SmarterX and Advertising AI Institute founder and CEO Paul Roetzer on Episode 176 of The Artificial Intelligence Show.

    A Harmful New Assault Floor

    Whereas options like browser recollections and an experimental agent mode sound helpful, cybersecurity consultants warn they’re weak to immediate injection assaults.

    The core concern is that the AI agent can fail to differentiate between a consumer’s trusted directions and malicious, typically hidden, directions embedded in a webpage.

    This successfully “collapses the boundary between information and directions,” as one skilled famous in Fortune. A hidden immediate on an internet site might hijack the Atlas agent to exfiltrate a consumer’s emails, overwrite their clipboard with malicious hyperlinks, and even provoke malware downloads, all with out the consumer’s information.

    Unseeable Assaults and Clipboard Hijacks

    This is not only a theoretical menace. Safety researchers are already demonstrating how these exploits work within the wild.

    The browser firm Courageous detailed how “unseeable immediate injections,” or malicious instructions hidden in faint textual content and even inside screenshots, could be learn and executed by AI brokers.

    One other researcher, often known as Pliny the Liberator, highlighted the vulnerability of “clipboard injection.” A consumer may assume they’re copying easy textual content from a webpage, however they may be copying hidden directions that command the AI agent to carry out a malicious motion the subsequent time they paste.

    As Courageous’s analysis factors out, if you’re signed into delicate accounts like your financial institution or electronic mail, merely asking the agent to summarize a Reddit publish might end in an attacker stealing your information or cash.

    An Unsolved Safety Drawback

    The safety neighborhood’s backlash was so swift that OpenAI’s Chief Info Safety Officer, Dane Stuckey, launched a public statement.

    Whereas Stuckey famous that the corporate carried out “intensive red-teaming” and carried out “overlapping guardrails,” he additionally made a crucial admission: immediate injection stays a “frontier, unsolved safety downside.”

    This response was telling.

    “You might inform this turned a difficulty actual quick,” says Roetzer. “That is very clearly not secure for work stuff.”

    The Enterprise Takeaway: “Do Not Flip This On”

    For any enterprise chief or skilled questioning if they need to attempt Atlas, Roetzer’s recommendation is unequivocal.

    “Because the CEO of an organization my very first thing is like: don’t flip this on. Don’t use this until it is in a really managed atmosphere and we all know what we’re doing,” he says.

    Past energetic assaults, the essential privateness implications are huge. Atlas’s browser recollections characteristic works by summarizing internet content material on OpenAI’s servers. Whereas the corporate claims it applies filters designed to maintain out personally identifiable info (PII) like social safety or checking account numbers, the important thing phrase is “designed.” 

    “You are actually trusting OpenAI that their filters work,” Roetzer notes. “And that that stuff would not find yourself someplace you do not need it to. Simply to make this tremendous clear to everyone, they monitor all the pieces you do. It remembers all the pieces you do, together with your entire private info and exercise, and it summarizes all of that until their information filters work appropriately.”

    Roetzer additionally pointed to a complicated setting that appears to indicate customers can determine whether or not OpenAI can use third-party copyrighted content material they browse to coach its fashions.

    The Finish Aim vs. At present’s Actuality

    It is clear what OpenAI is making an attempt to construct.

    “They’re making an attempt to shift habits and actually get you to deal with ChatGPT as a platform on your life and your work,” says Roetzer.

    However this new browser is only a very early, and really dangerous, step in that route. As famous programmer Simon Willison wrote, the “safety and privateness dangers concerned right here really feel insurmountably excessive to me.”

    The underside line for now? Experiment at your personal danger.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article“We will never build a sex robot,” says Mustafa Suleyman
    Next Article Meet ChatGPT Atlas, OpenAI’s Agentic Web Browser
    ProfitlyAI
    • Website

    Related Posts

    Latest News

    An Anthropic Merger, “Lying,” and a 52-Page Memo

    November 14, 2025
    Latest News

    Apple’s $1 Billion Bet on Google Gemini to Fix Siri

    November 14, 2025
    Latest News

    A Lawsuit Over AI Agents that Shop

    November 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    TruthScan vs Undetectable AI: Can TruthScan Win Over AI Humanizers?

    October 6, 2025

    Confusion Matrix Made Simple: Accuracy, Precision, Recall & F1-Score

    July 30, 2025

    Designing Trustworthy ML Models: Alan & Aida Discover Monotonicity in Machine Learning

    August 21, 2025

    How to Benchmark LLMs – ARC AGI 3

    July 31, 2025

    Apple’s AI Promises Just Got Exposed — Here’s What They’re Not Telling You

    April 23, 2025
    Categories
    • AI Technology
    • AI Tools & Technologies
    • Artificial Intelligence
    • Latest AI Innovations
    • Latest News
    Most Popular

    Changing the conversation in health care | MIT News

    July 9, 2025

    Applications of Density Estimation to Legal Theory

    June 10, 2025

    Using generative AI, researchers design compounds that can kill drug-resistant bacteria | MIT News

    August 14, 2025
    Our Picks

    TDS Newsletter: How Compelling Data Stories Lead to Better Business Decisions

    November 15, 2025

    I Measured Neural Network Training Every 5 Steps for 10,000 Iterations

    November 15, 2025

    “The success of an AI product depends on how intuitively users can interact with its capabilities”

    November 14, 2025
    Categories
    • AI Technology
    • AI Tools & Technologies
    • Artificial Intelligence
    • Latest AI Innovations
    • Latest News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2025 ProfitlyAI All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.