Story perspectives
Vulnerability Found in OpenAI's ChatGPT Atlas Browser
10/28/2025
1 of 1
Story summary
- LayerX Security identifies a vulnerability in OpenAI's ChatGPT Atlas browser that could enable remote code execution.
- The Cross-Site Request Forgery (CSRF)-based exploit hijacks authenticated sessions.
- Atlas blocks 5.8% of phishing, versus 47–53% for traditional browsers.
- OpenAI is investigating the issue now.
- Users should limit sensitive activities on Atlas and monitor the browser's memory for unauthorized actions.
