AI Browser Agents Can Be Hijacked by a Single Comment
Researchers hijacked ChatGPT Atlas with one planted comment on an X thread, then steered it through the victim’s logged-in accounts. OpenAI says this class of attack is unlikely to ever be fully solved. The fix small business owners actually control is not a patch, it is which accounts the agent can see.
