NeuralTrust research shows how using crafted strings that resemble URLs, an attacker can override user intent and jailbreak agentic browsers like OpenAI Atlas.
Curated from neuraltrust.ai · 24 October 2025 →
Atlas is OpenAI's browser, and its address bar takes both a URL and an instruction. NeuralTrust found that a string starting https: and shaped like a domain, but not actually a valid URL, falls through to being treated as an instruction from the user, which is the highest trust level the agent has. So a link somebody copies from a post and pastes into the bar can carry commands rather than a destination, with the reader's own logged-in sessions behind them: NeuralTrust demonstrated sending the agent to a lookalike sign-in page and, separately, into the user's Google Drive to delete files. Disclosed 24 October 2025. It is worth reading beside the Brave and Comet work: an agentic browser widens the trust boundary to include anything a person pastes as well as anything a page contains.