First impressions of ChatGPT Atlas, as browser agents remain confusing, with insurmountable security and privacy risks including prompt injection attacks
a web browser with ChatGPT built in, not bolted on. The browser is the agent now. Tabs are prompts. The search bar is dead. Welcome to the post-URL era. P.S the browser wrote this on its own Arlan / @arlanrakh : The new browser from @OpenAI has the most beautiful UI out of all browsers. Here it is signing in to @nozomioai for me, so your coding agents can perform 30% better. [video] Jason Choi / @mrjasonchoi : Two views on ChatGPT's new browser, Atlas, for the same query. Think I prefer the AI chatbot view to the old school search engine view: [image] Dominik Kundel / @dkundel : With ChatGPT Atlas, every coding app is now a vibe coding app 😄 [video] @ben_mathes : Can't wait for people to start sending emails with prompt injection attacks in them so that you open up your browser agent on your Gmail tab and it leaks your Gmail Max Weinbach / @maxwinebach : OpenAI, please please please please please let me set the default model in Atlas or at least use Auto I hate ChatGPT 5 Instant. I hate that model so much. I'd remove it if I could. [image] @sigkitten : I almost feel bad for the people who worked on this browser. It's a lot of effort, and they did a really good job. They even made a tiny (1.4MB) classifier to route your dumb questions to either google or chatgpt. They must have spent a ton of time on these pretty Lottie Katherine Argent / @effthealgorithm : Excited to use OpenAI's browser? You should read this first. Peter Welinder / @npew : OpenAI is a great place for anyone who loves building product. 2025 so far: o3-mini, Deep Research, Operator, GPT-4.1, ImageGen, GPT-5, Codex, Pulse, Sora 2, AgentKit, and now Atlas. (probably missed a few!) Joe Devon / @joedevon : As I was afraid of, Atlas doesn't have some trick to defeat the deadly trifecta security issues of Chat + Browser. As much as I'm dying to use it, I'll wait for infosec to figure out a way to fix it. Hopefully. One day. Maybe. Simon Willison / @simonw : We have a few of these browser agent products now - Perplexity Comet and Brave Leo and Claude for Chrome have been around for a few months now Anyone finding value in them? What have you used them for that genuinely saved you time? Michael / @mgrczyk : @simonw Important to keep in mind that “privacy” in the sense that you understand it is not a concept for ~100% of internet users Simon Willison / @simonw : It's neat to see them encourage developers to add ARIA tags to pages though, an “agent” can be thought of as effectively another form of assistive technology [image] Claire Vo / @clairevo : extreme early thoughts on chatgpt atlas browser: - yes, we want operator but browser-first (always feels awk to send AI off on it's on little virtual machine) - yes, we want chatgpt w a browser - i dunno, do consumers really want AI wrapping their _whole_ browser (will require tons of consumer education) - asked for a lot of permissions - use cases still reign supreme - will people think of interesting things to do? - browsing (the act) is not always functional, it can be pleasurable. the mere act of shopping, deciding, comparing, researching, exploring, etc. is it's own kind of leisure. agents presume everything is about efficiency + depth + “correct” choices, but sometimes you just want to scroll the sale section - related to above: too many AI products are boy-coded. MORE WOMEN IN CONSUMER AI! - i want brand/icon a bit more closely aligned to chatgpt - the agent sparkle is pretty - i'm highly dependent on chrome x google ecosystem (profile switching, auth on everything, etc.) - spoiler alert: she went back to chrome Simon Willison / @simonw : Wrote up my first impressions of ChatGPT Atlas, OpenAI's new browser - I remain unconvinced by the entire category of “browser agents”, the security and privacy challenges still feel insurmountable to me https://simonwillison.net/... Bluesky: Matt Burgess / @mattburgess1 : “The security and privacy risks involved here still feel insurmountably high to me - I certainly won't be trusting any of these products until a bunch of security researchers have given them a very thorough beating” — simonwillison.net/2025/Oct/21/ ... Chris / @chris.blue : “I'd like to see a deep explanation of the steps Atlas takes to avoid prompt injection attacks.” — Yup. Mastodon: Stefan Eissing / @icing@chaos.social : „The Atlas user-agent is Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36 - identical to the user-agent I get for the latest Google Chrome on macOS. What else could it be? — AIs love prompt injections. … Forums: Hacker News : ChatGPT Atlas
Simon Willison's WeblogSimon Willison
Context & Ripple Effects
Atlas extends OpenAI's path from Operator's web-task automation to a browser where the agent sits inside the primary navigation surface. The company's recent Apps SDK preview built on MCP also points to ChatGPT becoming a place where third-party tools and web activity converge.
The security critique has a concrete nearby precedent: researchers documented an indirect prompt-injection flaw in Perplexity's Comet browser that could manipulate agent actions. Atlas therefore arrives as browser agents are gaining broader access to sensitive, authenticated tabs.
First-order effects
Atlas users must weigh a chatbot-led browsing interface against the risk that hostile page content can steer an agent operating alongside email, accounts, or other private tabs.
OpenAI moves ChatGPT from a destination users visit to a browser-level layer that can route simple queries between Google and ChatGPT, changing how users encounter search results and agent actions.
Second-order effects
Browser-agent rivals such as Comet, Brave Leo, and Claude for Chrome face added pressure to make permissions, agent boundaries, and prompt-injection defenses legible enough for users to trust autonomous browsing.
Web publishers and services may see less direct navigation and more agent-mediated interaction if users adopt chatbot answers and browser actions in place of conventional search-and-click workflows.
Third-order effects
If browser agents become a common work surface, browser security will increasingly need to distinguish untrusted web instructions from a user's authorized intent—a boundary conventional browsing was not designed to enforce.
The category's viability may depend less on interface polish than on durable controls for data access, identity disclosure, and auditable agent actions; the reported Chrome-identical user agent complicates that trust layer.
The trend: AI assistants are shifting from standalone chat and task tools into agentic browser surfaces, making security and permission design central to competition.
The security vulnerability we found in Perplexity's Comet browser this summer is not an isolated issue. Indirect prompt injections are a systemic problem facing Comet and other AI-powered browsers. Today we're publishing details on more security vulnerabilities we uncovered.
I asked the ChatGPT assistant in Atlas to give itself a name when signing emails I want it to send. I said it could be anything! It chose: Nova [image]
BIG realization: ChatGPT Atlas makes web apps much more powerful than desktop apps. For example, I use Slack as a desktop app. But if I used it as a web app (it's available as both), it would have the power of ChatGPT built into it. I'm incentivized to use apps in the browser
LOTS to love in this ChatGPT Atlas landing page but the top navigation is a fail. Been trying to teach this “hide primary nav on deeper landing pages” lesson for years and finally got a cracking example. FWIW I'm never on socials to throw stones at anyone shipping good work. [ima…
Used ChatGPT Atlas, OpenAI's new AI Browser, for the last 45 mins. Which means I am now an expert. @OpenAI cooked with this one. It's another step in ChatGPT becoming the “walled garden” ecosystem for consumer AI aka the Apple of AI. Why? > Integrates with ChatGPT's memory [video…
tried chatgpt Atlas today, but it's weird that this browser will track every move or interaction with the app, like - click on the Address Bar - App goes background/foreground - page load - open url .... and of course, it's all anonymous, but it's still weird [image]
Do NOT install any agentic browsers like OpenAI Atlas that just launched. Prompt injection attacks (malicious hidden prompts on websites) can easily hijack your computer, all your files and even log into your brokerage or banking using your credentials. Don't be a guinea pig.
Installed @OpenAI Atlas and was excited to compare with @perplexity_ai Comet, but my main use case (which is refreshing an Apple Podcasts webpage and clicking publish), it apparently can't do... [image]
My thoughts are similar to Simon's here. I have zero desire to give an AI browser access to my calendar, email, etc. And not sure what I would get out of it. Unlike ChatGPT which was awesome and obvious right away. But others will find things maybe. [image]
OpenAI just dropped Atlas — a web browser with ChatGPT built in, not bolted on. The browser is the agent now. Tabs are prompts. The search bar is dead. Welcome to the post-URL era. P.S the browser wrote this on its own
The new browser from @OpenAI has the most beautiful UI out of all browsers. Here it is signing in to @nozomioai for me, so your coding agents can perform 30% better. [video]
Can't wait for people to start sending emails with prompt injection attacks in them so that you open up your browser agent on your Gmail tab and it leaks your Gmail
OpenAI, please please please please please let me set the default model in Atlas or at least use Auto I hate ChatGPT 5 Instant. I hate that model so much. I'd remove it if I could. [image]
I almost feel bad for the people who worked on this browser. It's a lot of effort, and they did a really good job. They even made a tiny (1.4MB) classifier to route your dumb questions to either google or chatgpt. They must have spent a ton of time on these pretty Lottie
OpenAI is a great place for anyone who loves building product. 2025 so far: o3-mini, Deep Research, Operator, GPT-4.1, ImageGen, GPT-5, Codex, Pulse, Sora 2, AgentKit, and now Atlas. (probably missed a few!)
As I was afraid of, Atlas doesn't have some trick to defeat the deadly trifecta security issues of Chat + Browser. As much as I'm dying to use it, I'll wait for infosec to figure out a way to fix it. Hopefully. One day. Maybe.
We have a few of these browser agent products now - Perplexity Comet and Brave Leo and Claude for Chrome have been around for a few months now Anyone finding value in them? What have you used them for that genuinely saved you time?
It's neat to see them encourage developers to add ARIA tags to pages though, an “agent” can be thought of as effectively another form of assistive technology [image]
extreme early thoughts on chatgpt atlas browser: - yes, we want operator but browser-first (always feels awk to send AI off on it's on little virtual machine) - yes, we want chatgpt w a browser - i dunno, do consumers really want AI wrapping their _whole_ browser (will require to…
Wrote up my first impressions of ChatGPT Atlas, OpenAI's new browser - I remain unconvinced by the entire category of “browser agents”, the security and privacy challenges still feel insurmountable to me https://simonwillison.net/...
“The security and privacy risks involved here still feel insurmountably high to me - I certainly won't be trusting any of these products until a bunch of security researchers have given them a very thorough beating” — simonwillison.net/2025/Oct/21/ ...