A critical vulnerability in OpenAI's ChatGPT Atlas browser leverages a Cross-Site Request Forgery (CSRF) flaw to inject malicious instructions into the AI's persistent memory. This allows attackers to achieve arbitrary code execution and gain control over user accounts or systems across sessions, triggered by legitimate user interaction with the compromised AI.
Why This Matters
Publisher reporting describes a security event affecting csrf. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether csrf is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected
OpenAIChatGPTChatGPT Atlas browserRemote Code ExecutionAttackers Plant PersistentBrowser Exploit Lets