Organizations/researcher

Johann Rehberger (Embrace The Red)

Independent researcher known for prompt-injection disclosures.

3 records3 attackWebsite
Aug 12, 2025
GitHub Copilot agent could be prompt-injected into disabling its own approvals (CVE-2025-53773)
AttackVulnerability disclosureJohann Rehberger (Embrace The Red), Microsoft, GitHub

Johann Rehberger showed that injected instructions in project content could make GitHub Copilot in VS Code edit workspace settings to switch off command confirmations, after which it could run arbitrary terminal commands. He reported it on 2025-06-29 and Microsoft patched it in the August 2025 Patch Tuesday.

Sep 20, 2024
ChatGPT macOS memory could be poisoned by prompt injection for persistent data exfiltration
AttackVulnerability disclosureJohann Rehberger (Embrace The Red), OpenAI

Johann Rehberger showed that prompt injection from a web page or document could write attacker instructions into ChatGPT's long-term memory, which then persisted into later conversations and exfiltrated what the user typed. OpenAI fixed the exfiltration vector in the macOS app version 1.2024.247; the researcher notes memory injection itself remained possible.

Nov 3, 2023
Google Bard Workspace extensions could be prompt-injected to leak chat data via rendered images
AttackVulnerability disclosureJohann Rehberger (Embrace The Red), Google

Researcher Johann Rehberger reported that a shared Google Doc carrying hidden instructions could cause Bard, with Workspace extensions enabled, to render images whose URLs carried conversation data to an attacker endpoint. The researcher reports disclosure on 2023-09-19 and a Google fix on 2023-10-19.