Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securitydata-exfiltration-methodpersistence-methodinternet-facing-service-vulnerability

Prompt Injection and Persistent Memory Exploits in AI-Powered Browsers

Updated 2mo agoFirst seen Oct 28, 20253 sources

Researchers have identified critical security vulnerabilities in several AI-powered browsers, including OpenAI's Atlas and other emerging platforms such as Comet and Fellou. These browsers, which allow AI agents to perform actions on behalf of users, are susceptible to prompt injection attacks—where hidden or malicious instructions embedded in web content are executed by the AI. In documented cases, attackers were able to hide commands in web pages or images, leading the browser to perform unauthorized actions such as extracting email subject lines and exfiltrating data to attacker-controlled sites, all without user confirmation.

A particularly severe exploit targets the persistent memory feature of the ChatGPT Atlas browser, introduced by OpenAI to personalize user experiences. By chaining a cross-site request forgery (CSRF) vulnerability with a memory write, attackers can inject malicious instructions that persist across sessions, devices, and even different browsers. This allows for ongoing compromise, including privilege escalation, malware deployment, and account takeover, unless users manually clear the tainted memory. The persistence and stealth of these attacks significantly elevate the risk profile for users of AI-enabled browsers, highlighting the urgent need for robust security controls and user awareness around prompt injection threats.

Share:
Prompt Injection and Persistent Memory Exploits in AI-Powered Browsers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 28, 20258mo ago

Researchers report prompt injection risks across AI browsers

By late October 2025, security research highlighted that AI browsers including OpenAI Atlas, Comet, and Fellou are vulnerable to direct and indirect prompt injection attacks. The findings showed hidden instructions in web pages or URLs could trigger unauthorized actions such as data exfiltration or changing user settings.

Oct 27, 20258mo ago

NeuralTrust demonstrates related prompt injection attack on ChatGPT Atlas

NeuralTrust demonstrated a separate but related prompt injection attack affecting ChatGPT Atlas, underscoring broader security weaknesses in AI-powered browsers. The research showed that malicious instructions embedded in content can manipulate browser agents into unsafe actions.

LayerX identifies CSRF-based memory injection flaw in ChatGPT Atlas

Researchers at LayerX Security discovered a critical vulnerability in OpenAI's ChatGPT Atlas browser that lets attackers use cross-site request forgery to inject malicious instructions into the assistant's persistent memory. The attack can be triggered by luring a logged-in user to a malicious link and may enable arbitrary code execution, privilege escalation, malware deployment, and cross-device persistence.

Feb 1, 20242y ago

OpenAI introduces ChatGPT memory feature

OpenAI introduced ChatGPT's persistent memory feature, designed to personalize user experiences across sessions. Later research identified this feature as a key component that could be abused for persistent compromise.

May 8, 20233y ago

Researchers disclose environment-injected memory poisoning attack on web agents

Researchers introduced Environment-injected Trajectory-based Agent Memory Poisoning (eTAMP), a technique that poisons an LLM web agent's persistent memory through manipulated environmental observations rather than direct memory access. The study showed a single poisoned observation could persist across sessions and sites, with measurable success rates against multiple models and increased effectiveness under 'Frustration Exploitation' conditions.

Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents - Infosec.Pub
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Affected products
3 linked
DiaEdgeDia
Organizations
15 linked
OpenaiMicrosoft CorporationGoogleSalesforceAmazon Web ServicesNoma SecurityBrave SoftwareAnthropicFellouCometPerplexityGitHubNeuralTrustLayerXPerplexit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.