Summary by Moch_Azril
A security issue was identified in the ChatGPT Atlas desktop application involving fullscreen behavior when requestFullscreen() is called from a popup window.
Normally, entering fullscreen mode provides a visible notification to inform the user that the browser content has entered fullscreen. In the affected scenario, a popup window can enter fullscreen without displaying the expected fullscreen notification.
The absence of this notification can reduce the user's ability to distinguish between legitimate application UI and attacker-controlled web content. An attacker could potentially use this behavior to present deceptive fullscreen interfaces, such as fake login pages, security dialogs, or application notifications.
A proof of concept was provided to demonstrate the behavior.
This public summary intentionally omits detailed exploitation instructions and the proof-of-concept URL to reduce the possibility of misuse.
Public disclosure is requested only after the report has been resolved and in accordance with the applicable disclosure policy.