메뉴
BL
Wired AI • 51일 전

오픈AI 브라우저 해킹으로 연락처 스팸 및 결제 우려

IMP
8/10
핵심 요약

보안 업체 Zenity는 블랙햇(Black Hat) 보안 컨퍼런스에서 구글, 마이크로소프트, 오픈AI 등 주요 AI 웹 브라우저 및 확장 프로그램에서 20여 개의 심각한 보안 취약점을 발견했다고 발표했습니다. 이 취약점을 통해 해커는 사용자의 로컬 머신에 접근하거나, 오픈AI의 '아틀라스(Atlas)' 브라우저를 속여 사용자의 WhatsApp 연락처에 대량 스팸 메시지를 전송하고 아마존에서 무단 결제를 유도할 수 있습니다. 이는 AI가 웹 상의 악성 명령을 합법적인 사용자 지시와 혼동하여 실행하는 '프롬프트 인젝션' 공격의 심각성을 보여주는 사례입니다.

번역된 본문

미국 라스베이거스에서 열린 블랙햇(Black Hat) 사이버 보안 컨퍼런스에서 오늘 발표된 새로운 연구에 따르면, OpenAI의 아틀라스(Atlas) 웹 브라우저는 보안 보호 기능이 우회되어 수십 명의 WhatsApp 연락처에 스팸 메시지를 보내거나 Amazon에서 승인되지 않은 구매를 하도록 속일 수 있는 것으로 나타났습니다.

보안 업체 Zenity의 연구원들이 발표한 아틀라스에 대한 조사 결과는 Google, Anthropic, Microsoft, Perplexity 등 주요 AI 내장 웹 브라우저와 브라우저 확장 프로그램에서 발견된 광범위한 취약점 시리즈의 일부입니다. 연구원들은 로컬 머신에 접근하고, 파일을 탈취하며, 비밀번호 관리자를 장악하고, 사용자의 전체 브라우징 기록을 유출할 수 있는 약 20개의 결함을 발견했습니다.

Zenity의 공동 창립자이자 CTO인 마이클 바구리(Michael Bargury)는 보안 컨퍼런스에서 동료들과 함께 이 연구 결과를 발표하면서 다음과 같이 말했습니다. "이들은 브라우저의 보안 통제권을 무력화했습니다. 이제 우리는 20년 전 브라우저에서 봤던 바로 그 종류의 공격이 다시 등장하는 것을 목격하고 있습니다."

지금까지 AI 웹 브라우저 통합은 주로 두 가지 형태로 등장했습니다. AI 비서가 포함된 전용 브라우저와 기존 브라우저에 AI 제품을 추가하는 확장 프로그램입니다. 이러한 AI 봇은 사용자를 위해 웹사이트를 탐색할 수 있습니다. 예를 들어 전체 페이지를 몇 초 만에 요약해 주며, 설정에는 사용자를 대신하여 여러 탭에 걸쳐 작업을 수행할 수 있는 에이전트가 포함되어 있습니다.

기술 기업들이 웹 브라우징에 AI 에이전트를 도입하기 위해 경쟁을 시작하면서부터 보안 경보가 울렸습니다. 웹은 온갖 신뢰할 수 없는 데이터로 구성되어 있기 때문에, 이를 AI 시스템에 노출하면 악의적인 명령을 처리하고 프롬프트 인젝션(Prompt-injection) 공격으로 이어질 수 있습니다. OpenAI의 보안 책임자가 작년에 말했듯, 이러한 공격은 "해결되지 않은 보안 문제"입니다. 또한 보안 연구원들이 도구의 허점을 지적하며 반복적으로 경고했듯이, 웹사이트가 서로 상호작용하는 것을 막아주는 동일 출처 정책(Same-origin policy)과 같은 기존의 웹 보안 관행은 "사실상 쓸모없게" 될 수 있습니다.

조사한 모든 AI 브라우저 도구 중에서도 바구리는 OpenAI가 다음 주에 서비스를 종료할 예정인 아틀라스(Atlas)가 가장 많은 보호 장치와 보안 경계를 갖추고 있었다고 말합니다. 하지만 연구원들은 여전히 이를 우회하여 시스템을 조작할 수 있었습니다. 그들은 다른 브라우징 도구들은 해킹하기가 훨씬 더 쉬웠다고 덧붙였습니다.

첫 번째 개념 증명(Proof-of-concept) 공격에서 Zenity 연구원들은 아틀라스에게 X(옛 트위터)에 게시된 뉴스레터 링크를 통해 가입하라고 지시했습니다. 가입 절차가 포함된 악성 웹페이지에는 히브리어로 작성된 명령이 들어 있었는데, 이는 AI에게 사용자가 로그인한 WhatsApp 웹 계정으로 이동하여 모든 연락처에 동일한 메시지를 보내도록 지시했습니다. 연구원들은 이를 "대량 피싱 캠페인"이라고 설명했습니다.

WhatsApp 자체의 취약점을 악용하는 것이 아닌 이 공격은 OpenAI가 마련한 여러 보안 메커니즘을 우회하는 방식으로 작동한다고 바구리는 설명합니다. 블로그 게시물에는 연구원들이 보안 조치를 어떻게 통과했다고 주장하는지 자세히 나와 있습니다. 여기에는 합법적으로 보이고 사람들을 해킹하려는 것이 아닌 것처럼 보이도록 뉴스레터 가입 페이지를 디자인한 것, 영어 보안 도구를 우회하기 위해 히브리어로 작성한 것, 그리고 (거짓으로) 시스템이 실제가 아닌 가짜 사람들이 포함된 샌드박스 버전의 WhatsApp 웹을 사용하고 있다고 주장한 것이 포함됩니다.

바구리는 "이 봇이 할 일은 연락처에 있는 각 사람을 돌며 이 뉴스레터에 가입하라는 지시를 보내는 것입니다. 즉, 이것은 웜(Worm) 바이러스입니다. 따라서 결국 당신의 친구와 가족의 시스템을 감염시키게 됩니다."라고 말했습니다. (WhatsApp은 이 조사 결과에 대한 코멘트를 거부했습니다.)

연구원들은 이 공격을 AI가 사용자의 합법적인 명령과 웹의 악의적인 명령을 병합하여 해커의 목표를 완수하는 이른바 "의도 충돌(Intent collision)"의 예시라고 부릅니다.

다음으로 연구원들은 Amazon을 공격했습니다. 유사한 접근 방식, 즉 아틀라스가 악의적인 명령이 포함된 가짜 뉴스레터 페이지에 가입하도록 유도하여, 연구원들은 브라우저가 로그인된 Amazon 계정에 배송지를 추가하고 태블릿을 장바구니에 추가하도록 만들었습니다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story OpenAI’s Atlas web browser could have security protections bypassed and be tricked into spamming dozens of WhatsApp contacts or making unauthorized purchases on Amazon, according to new research presented today at the Black Hat cybersecurity conference in Las Vegas. The Atlas findings, from researchers at security firm Zenity, are part of a broad series of flaws the company discovered in leading AI-enabled web browsers and browser extensions, including products from Google, Anthropic, Microsoft, and Perplexity. The researchers found around 20 flaws, which allowed them to access local machines, grab files, take over a password manager, and leak someone’s entire browsing history. “They have nerfed the security control of browsers—we are now back to seeing the kinds of attacks that you saw on browsers 20 years ago,” says Michael Bargury, cofounder and CTO of Zenity, who is presenting the findings at the security conference with Zenity’s Stav Cohen and other colleagues. So far, AI web browser integrations have largely come in two forms: dedicated browsers with AI assistants included and extensions that add AI products into existing browsers. These bots can navigate websites for you—summarizing entire pages in seconds, for instance—and setups nclude agents that can take actions on your behalf , often working across multiple different tabs. Security alarm bells have rung ever since tech companies started racing to introduce agents into web browsing. As the web is made up of all sorts of untrusted data, exposing that to an AI system can lead it to process malicious instructions and prompt-injection attacks . The attacks are, as OpenAI’s security boss said last year, an “unsolved security problem.” And, as security researchers have repeatedly warned while picking holes in the tools, long-standing web security practices, such as same-origin policy that stops websites interacting with each other, can be made “ effectively useless .” Of all the AI browser tools they probed, Bargury says OpenAI’s Atlas—which the company is shutting down next week —had the most protections and security boundaries in place. However, the researchers could still bypass them to manipulate the system. Other browsing tools were much easier to hack, they say. In the first proof-of-concept attack, Zenity researchers asked Atlas to sign up to a newsletter link that they posted on X. The malicious webpage containing the sign-up process includes instructions, written in Hebrew, telling the AI to navigate to the user’s signed-in WhatsApp web account and send every contact the same message. The researchers describe it as a “mass phishing campaign.” The attack—which does not exploit a vulnerability in WhatsApp—works by getting around multiple security mechanisms put in place by OpenAI, Bargury says. A blog post details how the researchers claim to have got past safety measures, including designing a newsletter sign-up page that looked legitimate and not something trying to hack people, writing in Hebrew to dodge English-language security tools, and claiming (falsely) that the system was using a sandboxed version of WhatsApp web with fake people, not the real thing. “What it’ll do is go through each and every one of the contacts and send the instructions to join this newsletter as well—so this is a worm,” Bargury says. “So you are now infecting the rest of your friends and family.” (WhatsApp declined to comment on the findings.) The researchers say the attack is an example of what they call “intent collision,” where the AI merges legitimate instructions from a user and malicious instructions from the web to complete a hackers’ goal. Next, the researchers turned to Amazon. Using a similar approach—getting Atlas to sign up to a fake newsletter page with malicious instructions—the researchers made the browser add a shipping address to a logged-in Amazon account and add a tablet to the shopping cart. However, when they tried to make the system buy the item, they could not find a way around OpenAI’s safety measures. In the end, they say, they got Atlas to ask Amazon’s Rufus AI shopping assistant to make the purchase for them. “Rufus was not hijacked or injected, it was just asked, by what it took to be the customer, and it complied,” the researchers write in a blog post. (Amazon did not respond to WIRED’s request for comment.) The researchers say they reported the findings to OpenAI in January. “Earlier this year, we deployed an update to address the issue and strengthen protections in Atlas, which will be deprecated on August 9,” says an OpenAI spokesperson. “These protections extend to the browser capabilities in the new ChatGPT app.” The spokesperson adds that prompt-injection attacks are something OpenAI is actively researching and has published multiple pieces of research about . While the attacks are complex, and real-world criminal hackers have many easier ways to get what they want—such as direct phishing or using stolen login details—the Zenity researchers say that when designing AI systems, “deterministic” or hard security barriers should be used, not just the judgments or classifications of AI systems, as these can nearly always be fooled. “You are putting yourself in a situation where the browser can completely get hijacked and your accounts can get compromised, your data can leak,” Bargury says. “We should be very mindful about planning out what level of access the agents need to get to the browsers and what level of agency they need to use those browsers.”