{"id":351060,"date":"2025-10-27T06:20:00","date_gmt":"2025-10-27T13:20:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=400154"},"modified":"2025-10-27T07:49:47","modified_gmt":"2025-10-27T14:49:47","slug":"if-you-have-switched-to-atlas-openais-browser-you-have-a-huge-security-gap-on-your-computer","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/if-you-have-switched-to-atlas-openais-browser-you-have-a-huge-security-gap-on-your-computer\/","title":{"rendered":"If you have switched to Atlas, OpenAI&#039;s browser, you have a huge security gap on your computer"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The newly launched Atlas web browser from OpenAI has been affected by a command injection attack that allows attackers to disguise malicious instructions as innocent URLs. According to a report from NeuralTrust, <strong>this vulnerability resides in the browser&#8217;s omnibox, which interprets user input both as a URL to navigate to and as a natural language command for the artificial intelligence agent<\/strong>.<\/p>\n\n\n<h2 class=\"wp-block-heading\">A problem of enormous magnitude<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Attackers can manipulate the omnibox by creating malformed URLs that start with &#8220;https&#8221; and contain domain text, followed by instructions that can execute harmful commands.<strong> If an unsuspecting user enters this misleading string into the omnibox, the browser may treat it as a high-trust command<\/strong>, allowing harmful actions, such as redirecting the victim to phishing pages or even deleting files from connected applications like Google Drive.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The CISO of OpenAI, Dane Stuckey, has acknowledged that command injection is an unresolved security issue that requires ongoing attention. Despite the company implementing training techniques and additional security measures to mitigate these risks, <strong>the challenge persists and could allow malicious actors to devise innovative ways to exploit this vulnerability<\/strong>.<\/p>\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Introducing ChatGPT Atlas\" width=\"840\" height=\"473\" src=\"https:\/\/www.youtube.com\/embed\/8UWKxJbjriY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\">Additionally, SquareX Labs has warned about a technique known as &#8220;AI sidebar sabotage,&#8221; which allows attackers to create malicious extensions to steal data or deceive users. <strong>This attack is triggered when commands are entered into a fake sidebar, highlighting how command injections are a growing concern in the security of browsers and artificial intelligence assistants.<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">The industry is recognizing command injection as a critical security issue. <strong>Companies like Perplexity and Brave have also reported the susceptibility of their browsers to these attacks<\/strong>, which indicates a fundamental shift in how security should be addressed in the field of artificial intelligence.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"ChatGPT\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/b330d2b7-464c-4693-b81d-2c97b1edf062\/857405465\/chatgpt-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">ChatGPT<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/chatgpt.softonic.com\/iphone\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/chatgpt.softonic.com\/iphone\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The newly launched Atlas web browser from OpenAI has been affected by a command injection attack that allows attackers to disguise malicious instructions as innocent URLs. According to a report from NeuralTrust, this vulnerability resides in the browser&#8217;s omnibox, which interprets user input both as a URL to navigate to and as a natural language command for the artificial intelligence agent. A problem of enormous magnitude Attackers can manipulate the omnibox by creating malformed URLs that start with &#8220;https&#8221; and contain domain text, followed by instructions that can execute [&#8230;]<\/p>\n","protected":false},"author":9318,"featured_media":351071,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[1401,17505,3746,5605,17662,17663,17664,17665,5668],"usertag":[],"vertical":[],"content-category":[7176],"class_list":["post-351060","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-ai","tag-atlas","tag-chatgpt","tag-ciberseguridad","tag-cracker","tag-dane-stuckey","tag-neuraltrust","tag-omnibox","tag-openai","content-category-seguridad-privacidad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/351060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=351060"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/351060\/revisions"}],"predecessor-version":[{"id":351073,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/351060\/revisions\/351073"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/351071"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=351060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=351060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=351060"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=351060"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=351060"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=351060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}