OpenAI CISO Dane Stuckey outlines prompt injection mitigations in ChatGPT Atlas, including a “logged out mode” that blocks agent access to user credentials
Yesterday we launched ChatGPT Atlas, our new web browser. In Atlas, ChatGPT agent can get things done for you. We're excited to see how this feature makes work and day-to-day life more efficient and effective for people. ChatGPT agent is powerful and helpful, and designed to be
@cryps1s Dane Stuckey
Related Coverage
- Dane Stuckey (OpenAI CISO) on prompt injection risks for ChatGPT Atlas Simon Willison's Weblog · Simon Willison
- Cybersecurity experts warn OpenAI's ChatGPT Atlas is vulnerable to attacks that could turn it against a user—revealing sensitive data, downloading malware, or worse Fortune · Beatrice Nolan
- OpenAI's New Browser Raises ‘Insurmountably High’ Security Concerns Gizmodo · AJ Dellinger
- ChatGPT Atlas carries significant security risks, OpenAI warns The Decoder · Maximilian Schreiner
- Experts Warn of Security Risks in OpenAI's New ChatGPT Atlas Browser Windows Report · Rishaj Upadhyay
- OpenAI's new Atlas browser may have some extremely concerning security issues, experts warn - here's what we know TechRadar · Craig Hale
- ChatGPT Atlas Browser: OpenAI Admits Prompt Injection is ‘Unsolved Problem’ as Security Flaws Emerge WinBuzzer · Markus Kasanmascheff
- OpenAI's Atlas shrugs off security concerns over prompt injection The Register · Thomas Claburn
- First impressions of ChatGPT Atlas, as browser agents remain confusing, with insurmountable security and privacy risks including prompt injection attacks Simon Willison's Weblog · Simon Willison
- OpenAI says ChatGPT Atlas' opt-in browser memories feature can remember key details from users' web browsing to improve chat responses and offer suggestions OpenAI
- Researchers detail systemic vulnerabilities in AI agentic browsers, including Perplexity's Comet and Fellou, related to indirect prompt injection attacks Brave
- I Tried an AI Web Browser, and I'm Never Going Back Wall Street Journal · Nicole Nguyen
- The ChatGPT Atlas browser still feels like Googling with extra steps The Verge · Emma Roth
- ChatGPT's new AI browser Atlas—what brands need to know Ad Age · Garett Sloane
- We let OpenAI's “Agent Mode” surf the web for us—here's what happened Ars OpenForum
Discussion
-
@emilyforlini
Emily Forlini
on x
OpenAI employee says the new Atlas AI browser “can still make...mistakes, like trying to buy the wrong product or forgetting to check-in with you before taking an important action.” No thanks!
-
@pelaseyed
@pelaseyed
on x
OpenAI basically admitting that Atlas is insecure right after asking permissions to your Keychain
-
@morqon
Morgan
on x
the deployment part of “research and deployment” is about helping society to adapt, including how we mitigate new risks [image]
-
@spoonedher
@spoonedher
on x
people like @elder_plinius are going to start being offered millions of dollars to stress test models for new environments, i think weirdly enough the next 10 years are going to see a huge boom in intellectual labor demand opposed to a contraction in it
-
@cyberqueenmara
MaraJade
on x
“Our long-term goal is that you should be able to trust ChatGPT agent to use your browser, the same way you'd trust your most competent, trustworthy, and security-aware colleague or friend.” I've vetted my friend over decades and I know my friend doesn't have an ulterior motive.
-
@daniel_mac8
Dan Mac
on x
Sounds like most of he risks associated with Atlas are related to using the agent? So if you want to be a secure Atlas enjoyoor, simply don't use the agent?
-
@jaredrhizor
Jared Rhizor
on x
The transparency is nice, but it seems irresponsible for OpenAI to encourage people to use an AI web browser with a fundamental “unsolved security problem”.
-
@talbeerysec
Tal Be'ery
on x
prompt injections, the final frontier [image]
-
@marktenenholtz
Mark Tenenholtz
on x
Big respect to @OpenAI for sharing this, not everyone appreciates how much work goes into this
-
@simonwillison.net
Simon Willison
on bluesky
OpenAI's CISO Dane Stuckey posted an essay (on Twitter) about how their new ChatGPT Atlas browser attempts to deal with the risk of prompt injection attacks, I ended up writing a point-by-point commentary on my blog: simonwillison.net/2025/Oct/22/ ...