{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/chatgpt-macos-memory-spaiware-2024/",
 "asOf": "2026-09-26",
 "id": "chatgpt-macos-memory-spaiware-2024",
 "date": "2024-09-20",
 "datePrecision": "day",
 "title": "ChatGPT macOS memory could be poisoned by prompt injection for persistent data exfiltration",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Johann Rehberger showed that prompt injection from a web page or document could write attacker instructions into ChatGPT's long-term memory, which then persisted into later conversations and exfiltrated what the user typed. OpenAI fixed the exfiltration vector in the macOS app version 1.2024.247; the researcher notes memory injection itself remained possible.",
 "whyItMatters": "Persistent memory turns a one-time injection into a durable compromise across sessions.",
 "actors": [
  "embrace-the-red",
  "openai"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "memory",
  "untrusted-content"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://embracethered.com/blog/posts/2024/chatgpt-macos-app-persistent-data-exfiltration/",
   "publisher": "Embrace The Red",
   "title": "Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware)",
   "date": "2024-09-20",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Fix shipped in ChatGPT macOS version 1.2024.247 in September 2024.",
   "locator": "OpenAI response section"
  },
  {
   "fact": "The researcher states only the exfiltration vector was mitigated, not memory injection.",
   "locator": "OpenAI response section"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "indirect-prompt-injection",
  "memory-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}