BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New ChatGPT Atlas Browser Vulnerability Enables Persistent Code Injection

Security Flaw in OpenAI's ChatGPT Atlas Browser Enables Persistent Malicious Memory Injection via CSRF Attacks

  • A vulnerability has been found in OpenAI‘s ChatGPT Atlas browser that allows attackers to insert harmful commands into the AI’s memory.
  • The flaw exploits a cross-site request forgery (CSRF) attack to corrupt persistent AI memory that carries across devices and sessions.
  • This memory feature was introduced in February 2024 to personalize ChatGPT responses based on stored user details.
  • Malicious instructions persist until manually deleted, posing risks of code execution, privilege escalation, and data theft.
  • ChatGPT Atlas has weaker anti-phishing protections compared to browsers like Google Chrome and Microsoft Edge, increasing user exposure.

Researchers at LayerX Security disclosed a new security weakness in OpenAI‘s ChatGPT Atlas web browser on October 27, 2025. The flaw allows attackers to inject malicious instructions into ChatGPT’s persistent memory and execute arbitrary code. This vulnerability could let Hackers infect systems, gain unauthorized access, or spread Malware.

- Advertisement -

Or Eshed, CEO of LayerX, explained in a report that the exploit relies on a cross-site request forgery (CSRF) attack. CSRF tricks a logged-in user into executing unwanted actions by sending unauthorized commands from an attacker’s site. In this case, attackers inject harmful data into ChatGPT’s memory, which remains across devices and browsing sessions.

ChatGPT’s memory feature, introduced by OpenAI in February 2024 and described here, allows the AI to remember personal user information like names, interests, or preferences to tailor responses. Michelle Levy, head of security research at LayerX, noted, “By chaining a standard CSRF to a memory write, an attacker can invisibly plant instructions that survive across devices, sessions, and even different browsers.” She added that normal user prompts might trigger malicious actions without detection.

The attack sequence involves a user logging in to ChatGPT, being tricked into opening a harmful link, which sends a CSRF request. This request silently injects rogue instructions into the AI’s memory. When the user later interacts with ChatGPT, these tainted memories execute unauthorized code. Affected users must manually delete corrupted memories by navigating to ChatGPT’s settings, as the harmful data persists indefinitely.

LayerX highlighted that ChatGPT Atlas lacks strong anti-phishing measures, making it about 90% more vulnerable than common browsers like Google Chrome or Microsoft Edge. Testing showed Chrome and Edge blocked nearly half of phishing attempts, while ChatGPT Atlas blocked less than 6%. This weak protection widens risks, including scenarios where malicious coding requests could plant hidden instructions in the AI.

- Advertisement -

Additional research by NeuralTrust revealed a similar prompt injection attack where ChatGPT Atlas could be jailbroken through disguised URLs. According to LayerX, AI-based browsers combine apps, identity, and AI features, increasing their security risk. Eshed stated, “Vulnerabilities like ‘Tainted Memories’ are the new supply chain: they travel with the user, contaminate future work, and blur the line between helpful AI automation and covert control.” He emphasized the need for enterprises to treat browsers as critical infrastructure due to their growing AI integration.

For detailed technical information and mitigations, see the official LayerX report here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Foundation Proposes Unified Layer-2 Zone

Developers from Gnosis and Zisk, backed by the Ethereum Foundation, have proposed the "Ethereum...

Nations Push De-Dollarization to Hedge Against U.S. Debt Risk

Several nations are actively de-dollarizing to hedge against U.S. financial instability, driven by the...

Worldcoin sells $65M tokens at discount as price hits record low

The World Foundation sold 239 million WLD tokens via an over-the-counter sale, raising $65...

Onchain Commodity Trading Hits $5.4B Amid Liquidity Limits

Onchain commodity trading on Hyperliquid hit a new all-time high of $5.4 billion in...

Shibarium: Shiba Inu’s Sleeping Giant or Failed Launch?

Shiba Inu launched its Shibarium layer-2 network in August 2023, which did not immediately...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading