Researchers at NeuralTrust found a major prompt injection flaw in OpenAI’s new Atlas browser that lets malicious links act as trusted commands. The vulnerability exposes a core security risk in “agentic browsers,” where AI agents can mistake harmful input for genuine user intent.
