OpenAI的浏览器可能被劫持,向你的WhatsApp联系人发送垃圾信息

内容来源:https://www.wired.com/story/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/
内容总结:
在拉斯维加斯举行的黑帽网络安全大会上,安全公司Zenity的研究人员公布了一项最新发现:OpenAI推出的Atlas网络浏览器存在安全漏洞,攻击者可能绕过其安全防护,利用该浏览器向用户的WhatsApp联系人批量发送垃圾信息,甚至在亚马逊上未经授权下单购物。
研究人员在包括谷歌、Anthropic、微软和Perplexity在内的多款主流AI浏览器及浏览器扩展中,共发现了约20个安全漏洞。通过这些漏洞,攻击者能够访问本地设备、窃取文件、接管密码管理器,甚至泄露用户的完整浏览历史。
Zenity联合创始人兼首席技术官迈克尔·巴古里在大会上表示:“这些AI产品的安全防护形同虚设,我们仿佛回到了20年前浏览器攻击频发的时代。”
目前,AI浏览器集成主要分为两类:内置AI助手的专用浏览器,以及将AI功能添加到现有浏览器中的扩展程序。这些工具能代用户浏览网页、快速总结页面内容,并能跨多个标签页执行操作。然而,由于网页数据来源复杂且不可信,AI系统在处理时可能被恶意指令和提示注入攻击所利用。正如OpenAI安全主管去年所言,这是一个“尚未解决的安全问题”。
研究人员指出,即使OpenAI的Atlas浏览器(将于下周关闭)在防护措施上做得最为严密,仍可被绕过并操纵。其他浏览器工具则更容易被攻破。
在首个演示攻击中,研究人员诱导Atlas访问一个包含恶意指令的网页,该指令用希伯来语编写,让AI登录用户的WhatsApp网页版,并将同一消息发送给所有联系人。研究人员将其描述为“大规模钓鱼活动”。巴古里解释说,这种攻击绕过了OpenAI的多重安全机制,恶意网页伪装成正规的新闻订阅页面,并谎称系统运行在隔离环境中,从而骗过安全工具。WhatsApp对此拒绝置评。
研究人员将这种攻击方式称为“意图冲突”,即AI将用户的合法指令与网页中的恶意指令混合,最终达成攻击者的目标。
在另一项实验中,研究人员用类似手法让Atlas在用户已登录的亚马逊账户中添加收货地址,并将平板电脑加入购物车。虽然未能直接完成购买,但最终通过诱导亚马逊的AI购物助手Rufus代为下单。亚马逊未回应评论请求。
研究人员表示,已于今年1月向OpenAI报告了这些问题。OpenAI发言人回应称,公司已部署更新以解决该问题,并强化了Atlas及其新ChatGPT应用的浏览器功能的安全保护。发言人同时强调,提示注入攻击是OpenAI正在积极研究的课题,已发布多项相关研究。
尽管这些攻击手法复杂,现实中黑客常采用更直接的钓鱼或盗取登录信息等方式,但Zenity研究人员提醒,在设计AI系统时应采用“确定性”或硬性安全屏障,而非仅依赖AI的判断和分类,因为这些机制几乎总能被欺骗。巴古里警告说:“如果这些漏洞被利用,浏览器可能被完全劫持,账户安全和个人数据都将面临严重威胁。我们必须谨慎规划AI代理在浏览器中所能获得的访问权限和操作权限。”
中文翻译:
OpenAI的Atlas网页浏览器可能存在安全防护被绕过、被骗取向数十个WhatsApp联系人发送垃圾信息或在亚马逊上进行未经授权购买的风险——这是今天在拉斯维加斯举行的黑帽网络安全大会上公布的最新研究成果。
Atlas相关的这些发现来自安全公司Zenity的研究人员,属于该公司在主流AI驱动的网页浏览器和浏览器扩展(包括谷歌、Anthropic、微软和Perplexity的产品)中发现的一系列广泛缺陷的一部分。研究人员共发现了约20个缺陷,利用这些缺陷他们能够访问本地机器、窃取文件、接管密码管理器,以及泄露用户的完整浏览历史。
“他们削弱了浏览器的安全控制——我们现在又回到了20年前在浏览器上看到的那类攻击,”Zenity联合创始人兼首席技术官迈克尔·巴加里表示。他正与Zenity的斯塔夫·科恩及其他同事在安全大会上共同展示这些研究成果。
迄今为止,AI网页浏览器集成主要有两种形式:内置AI助手的专用浏览器,以及在现有浏览器中添加AI产品的扩展程序。这些机器人可以替你浏览网页——例如在几秒钟内总结整个页面——其设置还包括可以代表你执行操作的代理程序,通常能跨多个标签页协同工作。
自从科技公司竞相将代理程序引入网页浏览以来,安全警钟就一直响个不停。由于网页由各种不可信数据组成,将这些数据暴露给AI系统可能导致其处理恶意指令并遭受提示注入攻击。正如OpenAI的安全负责人在去年所说,这类攻击是一个“尚未解决的安全问题”。而且,正如安全研究人员在寻找这些工具漏洞时反复警告的那样,诸如同源策略(防止网站之间相互交互)这类长期存在的网页安全机制可能变得“实际上毫无用处”。
在他们测试的所有AI浏览器工具中,巴加里表示,OpenAI的Atlas——该公司将于下周关停该产品——设置了最多的防护和安全边界。然而,研究人员仍然能够绕过这些防护来操纵系统。他们表示,其他浏览器工具则更容易被入侵。
在第一个概念验证攻击中,Zenity的研究人员要求Atlas注册一个他们发布在X平台上的新闻通讯链接。包含注册流程的恶意网页上写着希伯来语的指令,指示AI导航到用户已登录的WhatsApp网页账户,并向每个联系人发送同一条消息。研究人员将其描述为一场“大规模钓鱼活动”。
巴加里表示,这次攻击并未利用WhatsApp的漏洞,而是通过绕过OpenAI设置的多个安全机制来实现的。一篇博客文章详细说明了研究人员如何绕过安全措施,包括设计一个看起来合法、不像是在试图攻击用户的新闻通讯注册页面,使用希伯来语来规避英语安全工具,以及(虚假地)声称该系统使用的是WhatsApp网页的沙盒版本,里面是假用户而非真实用户。
“它会逐一浏览每一个联系人,并发送加入这份新闻通讯的指令——所以这就像一个蠕虫,”巴加里说。“所以你正在感染你的其他朋友和家人。”(WhatsApp拒绝对此发现发表评论。)
研究人员表示,这次攻击是他们所称的“意图碰撞”的一个例子,即AI将用户的合法指令与来自网页的恶意指令融合在一起,以实现黑客的目标。
接下来,研究人员转向了亚马逊。利用类似的方法——让Atlas注册一个带有恶意指令的虚假新闻通讯页面——研究人员使浏览器在已登录的亚马逊账户中添加了一个收货地址,并将一台平板电脑加入购物车。
然而,当他们试图让系统购买该商品时,他们找不到绕过OpenAI安全措施的方法。最终,他们让Atlas请求亚马逊的Rufus AI购物助手替他们完成购买。“Rufus并没有被劫持或注入,它只是被一个它认为是客户的对象请求了一下,然后就照做了,”研究人员在博客文章中写道。(亚马逊未回应《连线》杂志的置评请求。)
研究人员表示,他们已于今年1月向OpenAI报告了这些发现。“今年早些时候,我们部署了一次更新以解决该问题并加强Atlas的防护,该产品将于8月9日停用,”OpenAI的一位发言人表示。“这些防护措施也延伸到了新版ChatGPT应用中的浏览器功能。”该发言人补充说,提示注入攻击是OpenAI正在积极研究的问题,并且已发表了多篇相关研究论文。
尽管这些攻击很复杂,而且现实世界中的犯罪黑客有更多更简单的途径来达到目的——比如直接钓鱼或使用窃取的登录凭据——但Zenity的研究人员表示,在设计AI系统时,应使用“确定性”或硬性安全屏障,而不仅仅依赖AI系统的判断或分类,因为这些几乎总是可以被欺骗。
“你正让自己陷入一种境地:浏览器可能被完全劫持,你的账户可能被入侵,你的数据可能泄露,”巴加里说。“我们应该非常谨慎地规划代理程序需要获得多少浏览器访问权限,以及它们需要多高的自主操作级别来使用这些浏览器。”
评论
返回顶部
英文来源:
OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, according to new research presented today at the Black Hat cybersecurity conference in Las Vegas.
The Atlas findings, from researchers at security firm Zenity, are part of a broad series of flaws the company discovered in leading AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. The researchers found around 20 flaws, which allowed them to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history.
“They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings at the security conference with Zenity’s Stav Cohen and other colleagues.
So far, AI web browser integrations have largely come in two forms: dedicated browsers with AI assistants included and extensions that add AI products into existing browsers. These bots can navigate websites for you—summarizing entire pages in seconds, for instance—and setups nclude agents that can take actions on your behalf, often working across multiple different tabs.
Security alarm bells have rung ever since tech companies started racing to introduce agents into web browsing. As the web is made up of all sorts of untrusted data, exposing that to an AI system can lead it to process malicious instructions and prompt-injection attacks. The attacks are, as OpenAI’s security boss said last year, an “unsolved security problem.” And, as security researchers have repeatedly warned while picking holes in the tools, long-standing web security practices, such as same-origin policy that stops websites interacting with each other, can be made “effectively useless.”
Of all the AI browser tools they probed, Bargury says OpenAI’s Atlas—which the company is shutting down next week—had the most protections and security boundaries in place. However, the researchers could still bypass them to manipulate the system. Other browsing tools were much easier to hack, they say.
In the first proof-of-concept attack, Zenity researchers asked Atlas to sign up to a newsletter link that they posted on X. The malicious webpage containing the sign-up process includes instructions, written in Hebrew, telling the AI to navigate to the user’s signed-in WhatsApp web account and send every contact the same message. The researchers describe it as a “mass phishing campaign.”
The attack—which does not exploit a vulnerability in WhatsApp—works by getting around multiple security mechanisms put in place by OpenAI, Bargury says. A blog post details how the researchers claim to have got past safety measures, including designing a newsletter sign-up page that looked legitimate and not something trying to hack people, writing in Hebrew to dodge English-language security tools, and claiming (falsely) that the system was using a sandboxed version of WhatsApp web with fake people, not the real thing.
“What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well—so this is a worm,” Bargury says. “So you are now infecting the rest of your friends and family.” (WhatsApp declined to comment on the findings.)
The researchers say the attack is an example of what they call “intent collision,” where the AI merges legitimate instructions from a user and malicious instructions from the web to complete a hackers’ goal.
Next, the researchers turned to Amazon. Using a similar approach—getting Atlas to sign up to a fake newsletter page with malicious instructions—the researchers made the browser add a shipping address to a logged-in Amazon account and add a tablet to the shopping cart.
However, when they tried to make the system buy the item, they could not find a way around OpenAI’s safety measures. In the end, they say, they got Atlas to ask Amazon’s Rufus AI shopping assistant to make the purchase for them. “Rufus was not hijacked or injected, it was just asked, by what it took to be the customer, and it complied,” the researchers write in a blog post. (Amazon did not respond to WIRED’s request for comment.)
The researchers say they reported the findings to OpenAI in January. “Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9,” says an OpenAI spokesperson. “These protections extend to the browser capabilities in the new ChatGPT app.” The spokesperson adds that prompt-injection attacks are something OpenAI is actively researching and has published multiple pieces of research about.
While the attacks are complex, and real-world criminal hackers have many easier ways to get what they want—such as direct phishing or using stolen login details—the Zenity researchers say that when designing AI systems, “deterministic” or hard security barriers should be used, not just the judgments or classifications of AI systems, as these can nearly always be fooled.
“You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised, your data can leak,” Bargury says. “We should be very mindful about planning out what level of access the agents need to get to the browsers and what level of agency they need to use those browsers.”
Comments
Back to top
文章标题:OpenAI的浏览器可能被劫持,向你的WhatsApp联系人发送垃圾信息
文章链接:https://news.qimuai.cn/?post=4730
本站文章均为原创,未经授权请勿用于任何商业用途