Skip to main content
  1. Home
  2. Computing
  3. News

Your AI browser can be hijacked by prompt injection, OpenAI just patched Atlas

OpenAI says an internal automated red team uncovered a new class of agent-in-browser attacks, prompting a security update with a newly adversarially trained model and stronger safeguards.

Add as a preferred source on Google
A dark mystery hand typing on a laptop computer at night.
Andrew Brookes / Getty Images

OpenAI has shipped a security update to ChatGPT Atlas aimed at prompt injection in AI browsers, attacks that hide malicious instructions inside everyday content an agent might read while it works.

Atlas’s agent mode is built to act in your browser the way you would: it can view pages, click, and type to complete tasks in the same space and context you use. That also makes it a higher-value target, because the agent can encounter untrusted text across email, shared documents, forums, social posts, and any webpage it opens.

Recommended Videos

The company’s core warning is simple. Hackers can trick the agent’s decision-making by smuggling instructions into the stream of information it processes mid-task.

A hidden instruction, big consequences

OpenAI’s post highlights how quickly things can go sideways. An attacker seeds an inbox with a malicious email that contains instructions written for the agent, not the human.

Later, when the user asks Atlas to draft an out-of-office reply, the agent runs into that email during normal work and treats the injected instructions as authoritative. In the demo scenario, the agent sends a resignation letter to the user’s CEO, and the out-of-office never gets written.

If an agent is scanning third-party content as part of a legitimate workflow, an attacker can try to override the user’s request by hiding commands in what looks like ordinary text.

An AI attacker gets practice runs

To find these failures earlier, OpenAI says it built an automated attacker model and trained it end-to-end with reinforcement learning to hunt for prompt-injection exploits against a browser agent. The goal is to pressure-test long, realistic workflows, not just force a single bad output.

The attacker can draft a candidate injection, run a simulated rollout of how the target agent would behave, then iterate using the returned reasoning and action trace as feedback. OpenAI says privileged access to those traces gives its internal red team an advantage external attackers don’t have.

What to do with this now

OpenAI frames prompt injection as a long-term security problem, more like online scams than a bug you patch once. Its approach is to discover new attack patterns, train against them, and tighten system-level safeguards.

For users, you should use logged-out browsing when you can, scrutinize confirmations for actions like sending email, and give agents narrow, explicit instructions instead of broad “handle everything” prompts. If you’re still curious what AI browsing can do, then go with browsers that ship updates that benefit you.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Apple is finally bringing one of my favorite Continuity features to Windows
Your iPhone and Windows PC could soon share a clipboard.
Apple Universal Clipboard feature

I recently wrote about Apple’s Continuity features and how they play a big role in keeping me trapped inside the Apple ecosystem. One of the smallest but most-used and favorite Continuity features is the Universal Clipboard, which lets me copy and paste text and files between multiple Apple devices. 

Now, it seems that feature is finally coming to Windows PCs. As per MacRumors, Apple is reportedly working on letting you copy something on your iPhone and paste it straight into a Windows PC, no third-party app required. 

Read more
MSI’s new 4K 120Hz OLED monitor uses inkjet tech that could make premium screens cheaper
The first 27-inch 4K 120Hz IJP OLED monitor arrives through MSI and TCL CSOT
Computer Hardware, Electronics, Hardware

The future of OLED monitors may have just taken a significant step forward. MSI and TCL CSOT have unveiled the world’s first 27-inch 4K 120Hz desktop monitor built using inkjet-printed OLED technology, bringing a manufacturing method once limited to prototypes and specialist displays closer to everyday buyers.

Called the MSI Pro Max OLED 271UPJW12, the monitor uses a TCL CSOT panel created by printing organic light-emitting material directly onto the display. The process wastes less material than conventional OLED manufacturing and could eventually make panels cheaper and easier to produce at scale.

Read more
MSI launches a white 16-inch gaming laptop with a 12GB RTX 5070 and a pile of matching accessories
MSI bundles a mouse, headset, and extended mouse pad with its new white Crosshair gaming laptop
Adult, Female, Person

MSI has launched the Crosshair A16 HX MLG Edition globally, giving one of its upper mid-range gaming laptops a white-and-red makeover alongside a full set of matching accessories. MLG here stands for Mo-Loong-Gi, meaning “Dragon Princess,” and refers to an original character created by MSI rather than Major League Gaming.

What are you getting with this special edition laptop?

Read more