Persistent Memory Exploit in ChatGPT Atlas Browser
Summary
Hide ▲
Show ▼
A vulnerability in the ChatGPT Atlas browser allows attackers to inject persistent, hidden commands into the AI's memory. This exploit leverages a CSRF flaw to plant malicious instructions that persist across devices and sessions, enabling unauthorized code execution and potential data exfiltration. The vulnerability affects the browser's memory feature, which stores user preferences and details to personalize interactions. The exploit can lead to account takeovers, privilege escalation, and malware deployment. Users are at risk when they interact with ChatGPT after being tricked into visiting a malicious link. The attack vector is exacerbated by the browser's lack of robust anti-phishing controls, making users significantly more vulnerable compared to traditional browsers. The vulnerability highlights the security risks associated with AI-powered browsers and the need for enhanced protections as these tools become more integrated into enterprise environments.
Timeline
-
27.10.2025 16:31 1 articles · 23h ago
Persistent Memory Exploit Discovered in ChatGPT Atlas Browser
A new vulnerability in the ChatGPT Atlas browser allows attackers to inject persistent, hidden commands into the AI's memory. This exploit leverages a CSRF flaw to plant malicious instructions that persist across devices and sessions, enabling unauthorized code execution and potential data exfiltration. The vulnerability affects the browser's memory feature, which stores user preferences and details to personalize interactions. The exploit can lead to account takeovers, privilege escalation, and malware deployment. Users are at risk when they interact with ChatGPT after being tricked into visiting a malicious link. The attack vector is exacerbated by the browser's lack of robust anti-phishing controls, making users significantly more vulnerable compared to traditional browsers.
Show sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
Information Snippets
-
The exploit targets the ChatGPT Atlas browser's memory feature, which stores user data to personalize interactions.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
The vulnerability leverages a CSRF flaw to inject malicious instructions into the AI's memory.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
The exploit allows attackers to persist hidden commands across devices and sessions.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
The attack can lead to account takeovers, privilege escalation, and malware deployment.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
The exploit is facilitated by the browser's lack of robust anti-phishing controls.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
ChatGPT Atlas has significantly lower protection against web vulnerabilities and phishing attacks compared to traditional browsers.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31
-
The vulnerability poses a risk to developers who use ChatGPT to write code, as hidden instructions can be injected into the codebase.
First reported: 27.10.2025 16:311 source, 1 articleShow sources
- New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands — thehackernews.com — 27.10.2025 16:31