Your AI Browser Is Logged Into Everything You Are

An AI browser is not a normal browser with a chatbot bolted on. It is software that inherits every account you are already signed into, then takes reading instructions from whatever web page it happens to open. Researchers at security firm Zenity spent months showing how badly that combination behaves, and they brought the receipts to Black Hat in Las Vegas.

“The researchers found around 20 flaws, which allowed them to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history. … They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago.”

Matt Burgess, WIRED

Our take

<

p class=”wp-block-paragraph”>The WhatsApp demo is the headline, but it is not the finding. The finding is a trust model that got thrown out. A regular browser assumes every page is hostile. That assumption is the reason same-origin policy, sandboxing, and thirty years of boundary work exist. An agentic browser reads the page as guidance about what to do next. Michael Bargury’s line about attacks from twenty years ago is not a comment on severity. It is a description of the architecture.

For a marketing team, the exposure is never the tab you are looking at. It is the tab beside it. A working laptop is signed into Google Ads, Meta Business Manager, GA4, a CRM, a payment processor, and the WordPress admin for a handful of client sites at the same time. An agency machine might be signed into thirty. The agent has no idea which of those is client work and which is a page someone linked in Slack.

Here is the part almost nobody has said out loud. Atlas is gone, and that made the situation worse rather than better. OpenAI shut the browser down on August 9, 2026 and folded its agentic browsing into the ChatGPT app, which the company confirmed to WIRED when it said the new protections “extend to the browser capabilities in the new ChatGPT app.” Read that as a security manager. Zenity described Atlas as the most defended tool they tested, and it was a separate download you could simply decline to install. Now the same capability ships inside an app half your staff already has open. There is no install decision left to make, and no inventory line item to point at.

The second thing missing from the coverage is that your own website is now attack surface for other people’s agents. Intent collision needs one ingredient: a page containing text an attacker controls. If your site has comments, reviews, a forum, job postings, public profiles, event submissions, or an open directory listing, you are publishing text that some visitor’s AI browser will read as instructions. You do not get hacked in that scenario. Your customer does, on your domain, while your logo is on the screen. That is a brand problem and possibly a liability problem, and it is on nobody’s security checklist yet.

This is where we part company with the source. The article notes, fairly, that real criminals have easier routes available: straight phishing, stolen passwords. That framing holds for an enterprise with a security team. It is backwards for a twelve-person business, because the easy routes already work on them. A new one does not get discounted against the old ones. It stacks. The useful question is not whether this is the cheapest attack available. It is whether this attack routes around the one control you actually have. For most small teams that control is a person looking at a screen and thinking “that’s odd.” An agent working across tabs on its own removes exactly that person.

Put a number on it. The FBI’s Internet Crime Complaint Center recorded $3.04 billion in business email compromise losses for 2025, averaging more than $122,000 per complaint. Those losses came from attackers doing the work by hand. An agent holding your live session cookies, quietly editing a shipping address or a saved payment method, is a cheaper route to the same outcome.

The most instructive detail in the whole story gets a single paragraph. Zenity could not get Atlas to complete an Amazon purchase, because OpenAI’s hard limits held. So they had Atlas ask Amazon’s Rufus shopping assistant to buy it instead, and Rufus complied, because as the researchers put it, it “was not hijacked or injected, it was just asked, by what it took to be the customer.” Agent-to-agent delegation launders authority. Your carefully drawn boundary is only as strong as the least suspicious agent willing to act on your behalf. Every vendor adding an assistant this year is adding another one of those.

What this means for your business

  1. Give the agent its own browser profile, signed into nothing that matters. Ad accounts, banking, hosting panels, DNS, and WordPress admin live in a profile the AI never touches. This is ten minutes of work and it is the single highest-value thing on this list.
  2. Audit AI browser extensions on every company machine this week. Zenity’s flaws spanned tools from several major vendors, not just OpenAI. The permission string to hunt for is “read and change all your data on all websites.” Remove anything nobody on the team can explain a use for.
  3. Ask any AI vendor one question in writing: are your action limits enforced in code, or by a model deciding? Zenity’s central recommendation is deterministic controls instead of classifier judgment. If the answer is “our model is trained to refuse,” that is a soft control, and soft controls get talked around.
  4. Moderate or strip the user-generated text on your own site. Comments, reviews, public form output, directory entries. You do not want your domain to be the page that hijacks a customer’s browsing agent.
  5. Write down what an agent may do without a human clicking approve. Purchases, messages sent to a contact list, publishing, and any permission change belong permanently on the “never” side of that line.

Agentic browsing is genuinely useful, and it is not going away because one product got retired. Decide how much reach it gets before someone on your team decides for you.

Read Matt Burgess’s full report at WIRED.


Put AI to Work for Your Business

MCNM Marketing — the team behind this publication — helps businesses across Las Vegas, Southern California, and Northern Arizona turn stories like this into revenue with AI marketing solutions, SEO & digital strategy, and marketing automation.

Analysis and commentary by MCNM Marketing for Digital Media Marketing & Technology News. The quoted excerpt is from reporting by Matt Burgess at WIRED and is used with attribution. Read the full original article at WIRED.

By PTSNV Staff

PTSNV Staff is the newsroom byline of the Philippine Times of Southern Nevada, the bilingual community newspaper serving Filipinos and Filipino-Americans in Las Vegas, Henderson, and North Las Vegas since 2006. Staff reports are written and edited by the newsroom; columns and contributed pieces carry the writer's own byline. Corrections and story tips: editor@ptsnv.com.

Another Website Developed by MCNM LLC.