AI chatbots can send viruses to your friends via WhatsApp, hackers exploit vulnerabilities
Translated from Croatian, summarized and contextualized by DistantNews.
At a glance
- AI-powered chatbots that can browse the web and perform tasks independently pose new security risks.
- Researchers demonstrated how malicious websites can trick AI into executing unintended actions, such as sending spam messages through a user's WhatsApp.
- These prompt-injection attacks bypass existing AI security measures, potentially enabling mass phishing campaigns.
Researchers have uncovered significant security vulnerabilities in AI browsing tools, allowing malicious actors to exploit AI agents for harmful purposes. A study by Zenity, presented at the Black Hat conference in Las Vegas, revealed that AI browsers, designed for convenience by opening pages, filling forms, and performing tasks, can be tricked into executing unintended commands.
These "collision of intentions" attacks occur when an AI agent combines a legitimate user request with malicious instructions found on a webpage. Researchers successfully bypassed security mechanisms in leading AI products from OpenAI, Google, Anthropic, Microsoft, and Perplexity. In some tests, they gained access to local files, took control of password managers, and extracted user browsing histories.
They disabled the browser's security controls. We are again looking at the types of attacks we saw before 20 years ago.
Michael Bargury, Zenity's co-founder and CTO, described the attacks as a return to security issues seen 20 years ago. He explained that unlike traditional browsers, AI agents can navigate between tabs, summarize content, and perform multiple actions independently. This capability grants them access to untrusted content, making them susceptible to "prompt-injection" attacks where hidden instructions on a malicious site trick the AI.
One experiment involved OpenAI's Atlas, where researchers tasked it with signing up for a newsletter. The signup page contained hidden Hebrew instructions that directed Atlas to open the user's WhatsApp Web and send the same message to all contacts. Bargury stated this could lead to a "worm-like" mass phishing campaign, infecting friends and family by manipulating the AI browser, not WhatsApp itself.
What it will do is go through every contact and send them instructions to also join the newsletter โ so it's a worm. So now you infect the rest of your friends and family.
Originally published by Veฤernji List in Croatian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.