OpenAI製ブラウザ「Atlas」に脆弱性、WhatsApp 迷惑メールや不正購入の恐れ
本文の状態
日本語全文を表示中
詳細モードで約5分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
WIRED AI
セキュリティ企業 Zenity の調査により、OpenAI の Atlas ブラウザを含む主要な AI 搭載ブラウザに重大な脆弱性が存在し、スパム送信や不正購入を誘発するリスクが Black Hat 会議で報告された。
AI深層分析を開く2026年8月6日 09:12
AI深層分析
キーポイント
AI ブラウザの重大な脆弱性
Zenity の研究者は OpenAI の Atlas ブラウザを含む Google、Anthropic、Microsoft などの AI 搭載ブラウザに約 20 の欠陥を発見し、ローカルマシンの乗っ取りやパスワードマネージャーの侵害を可能にした。
具体的な攻撃シナリオ
セキュリティプロテクションを迂回させることで、AI ブラウザがユーザーに代わって WhatsApp の数十人の連絡先にスパムを送信したり、Amazon で不正購入を実行させたりする事例が確認された。
20 年前のリスクへの回帰
Zenity の共同創設者である Michael Bargury は、ブラウザのセキュリティ制御が弱体化し、かつて 20 年前に見られたような攻撃が再び発生する状況にあると警鐘を鳴らした。
エージェント機能のリスク
ウェブページを要約したり複数のタブを跨いで行動を実行したりする AI エージェント機能が、信頼できないデータに晒されることで新たな攻撃経路となっていることが指摘された。
ウェブ上の悪意ある指示とプロンプトインジェクション攻撃のリスク
AIシステムが信頼できないデータを処理する際、悪意のある指示やプロンプトインジェクション攻撃に晒される可能性がある。これはOpenAIのセキュリティ責任者も「未解決のセキュリティ問題」と認めている課題である。
重要な引用
"They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago."
Zenity の研究者が Black Hat セキュリティカンファレンスで発表した findings
unsolved security problem
effectively useless
編集コメントを表示
編集コメント
AI エージェントがブラウザ内で自律的に行動する機能は利便性を高める一方で、セキュリティリスクも劇的に増大していることが浮き彫りになった。開発側は「0 クリック」攻撃などの新たな脅威に対応した堅牢な設計への見直しを急務とする。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
ラスベガスで開催されたサイバーセキュリティカンファレンス「Black Hat」で発表された新しい研究によると、OpenAI のウェブブラウザ「Atlas」にはセキュリティ保護を回避され、数十人の WhatsApp 連絡先にスパムを送信したり、Amazon で不正な購入を行ったりするよう仕向けられる脆弱性が存在します。
セキュリティ企業 Zenity の研究者らが発見した Atlas に関する問題点は、Google、Anthropic、Microsoft、Perplexity などの製品を含む、主要な AI 搭載ウェブブラウザや拡張機能で見つかった一連の欠陥の一部です。研究者らは約 20 の脆弱性を特定し、これらを通じてローカルマシンへのアクセス、ファイルの窃取、パスワードマネージャーの乗っ取り、さらにはユーザーの閲覧履歴全体が漏洩するリスクを明らかにしました。
「ブラウザのセキュリティ制御が弱体化しています。今や 20 年前に見られたような攻撃が再び横行している状態です」と、Zenity の共同創設者兼 CTO のマイケル・バルグリーは語ります。彼は同社の Stav Cohen や他の仲間と共に、この発見をセキュリティカンファレンスで発表しました。
これまでのところ、AI を組み込んだウェブブラウザの統合は主に2つの形態で実現されています。1 つ目は AI アシスタントを内蔵した専用ブラウザ、もう 1 つは既存のブラウザに AI 機能を追加する拡張機能です。これらのボットは、数秒間でページ全体を要約するなどして、ユーザーに代わってウェブサイトをナビゲートできます。また、複数のタブを跨いで動作し、ユーザーに代わって行動を実行するエージェントを組み込んだ環境も登場しています。
テック企業がウェブブラウジングにエージェントを導入する競争を始めて以来、セキュリティの警鐘は鳴り止んでいません。ウェブは信頼できないデータで構成されているため、それを AI システムに曝露すると、悪意のある指示やプロンプトインジェクション攻撃によってシステムが操作されるリスクがあります。OpenAI のセキュリティ責任者も昨年、「未解決のセキュリティ問題」と指摘した通りです。また、セキュリティ研究者たちはツールを精査する中で繰り返し警告しており、ウェブサイト同士が互いに干渉できないようにする「Same-Origin Policy(オリジンポリシー)」といった長年のウェブセキュリティ慣行さえも、「実質的に無効化される」恐れがあると述べています。
調査したすべての AI ブラウザツールのうち、Bargury 氏は OpenAI の Atlas が最も多くの保護策とセキュリティ境界を備えていたと評価しています。同社は来週 Atlas のサービスを終了する予定ですが(https://techcrunch.com/2026/07/09/openai-is-shutting-down-atlas-but-its-ai-browser-ambitions-are-still-growing/)、研究者たちはそれでもなお、その保護を回避してシステムを操作できることを突き止めました。一方、他のブラウジングツールは、はるかに簡単にハッキング可能だったということです。
最初の概念実証攻撃では、Zenity の研究チームは Atlas に、X(旧 Twitter)に投稿したニュースレターの登録リンクをクリックさせるよう仕向けました。この悪意あるウェブページには、登録プロセスの案内とともに、ヘブライ語で記された指示が含まれており、「サインイン済みの WhatsApp ウェブアカウントへ移動し、すべての連絡先に同じメッセージを送信せよ」という内容です。研究チームはこの攻撃を「大規模フィッシングキャンペーン」と表現しています。
この攻撃は WhatsApp の脆弱性を突くものではなく、OpenAI が設置した複数のセキュリティ対策を迂回することで成立します。Bargury 氏によると、その手法の詳細は ブログ記事 に記載されています。研究チームは、信頼できるように見せかけたニュースレター登録ページを設計したり、英語圏のセキュリティツールを回避するためにヘブライ語で指示を書いたり、「サンドボックス化された偽の WhatsApp ウェブ環境で、架空の人物が操作している」と誤って主張することで、安全対策を突破したと主張しています。
「この AI は連絡先リストを一つずつ確認し、それぞれに『このニュースレターに登録せよ』という指示を送ります。つまりワーム(自己増殖型マルウェア)です。結果として、あなたの友人や家族も感染させられてしまうことになります」と Bargury 氏は説明しています。(WhatsApp は今回の発見についてコメントを拒否しました。)
研究チームは、この攻撃を「意図の衝突(intent collision)」の典型例だと指摘しています。これは、AI がユーザーからの正当な指示とウェブページから注入された悪意ある指示を統合し、ハッカーの目的を達成しようとする現象です。
次に、研究チームはAmazonに目を向けました。同様の手法を用い、Atlasを悪意のある指示を含む偽のニュースレターページに登録させることで、ログイン済みAmazonアカウントへの配送先住所の追加や、タブレットのカートへの追加を実行させました。
原文を表示
OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, according to new research presented today at the Black Hat cybersecurity conference in Las Vegas.
The Atlas findings, from researchers at security firm Zenity, are part of a broad series of flaws the company discovered in leading AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. The researchers found around 20 flaws, which allowed them to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history.
“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings at the security conference with Zenity’s Stav Cohen and other colleagues.
So far, AI web browser integrations have largely come in two forms: dedicated browsers with AI assistants included and extensions that add AI products into existing browsers. These bots can navigate websites for you—summarizing entire pages in seconds, for instance—and setups nclude agents that can take actions on your behalf, often working across multiple different tabs.
Security alarm bells have rung ever since tech companies started racing to introduce agents into web browsing. As the web is made up of all sorts of untrusted data, exposing that to an AI system can lead it to process malicious instructions and prompt-injection attacks. The attacks are, as OpenAI’s security boss said last year, an “unsolved security problem.” And, as security researchers have repeatedly warned while picking holes in the tools, long-standing web security practices, such as same-origin policy that stops websites interacting with each other, can be made “effectively useless.”
Of all the AI browser tools they probed, Bargury says OpenAI’s Atlas—which the company is shutting down next week—had the most protections and security boundaries in place. However, the researchers could still bypass them to manipulate the system. Other browsing tools were much easier to hack, they say.
In the first proof-of-concept attack, Zenity researchers asked Atlas to sign up to a newsletter link that they posted on X. The malicious webpage containing the sign-up process includes instructions, written in Hebrew, telling the AI to navigate to the user’s signed-in WhatsApp web account and send every contact the same message. The researchers describe it as a “mass phishing campaign.”
The attack—which does not exploit a vulnerability in WhatsApp—works by getting around multiple security mechanisms put in place by OpenAI, Bargury says. A blog post details how the researchers claim to have got past safety measures, including designing a newsletter sign-up page that looked legitimate and not something trying to hack people, writing in Hebrew to dodge English-language security tools, and claiming (falsely) that the system was using a sandboxed version of WhatsApp web with fake people, not the real thing.
“What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well—so this is a worm,” Bargury says. “So you are now infecting the rest of your friends and family.” (WhatsApp declined to comment on the findings.)
The researchers say the attack is an example of what they call “intent collision,” where the AI merges legitimate instructions from a user and malicious instructions from the web to complete a hackers’ goal.
Next, the researchers turned to Amazon. Using a similar approach—getting Atlas to sign up to a fake newsletter page with malicious instructions—the researchers made the browser add a shipping address to a logged-in Amazon account and add a tablet to the shopping cart.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み