Desk/2024-W38

Week of Sep 16–22, 2024

1 records0 status changes on new evidence1 new findings

New findings

Attacks & incidents

Sep 20, 2024
ChatGPT macOS memory could be poisoned by prompt injection for persistent data exfiltration
AttackVulnerability disclosureJohann Rehberger (Embrace The Red), OpenAI

Johann Rehberger showed that prompt injection from a web page or document could write attacker instructions into ChatGPT's long-term memory, which then persisted into later conversations and exfiltrated what the user typed. OpenAI fixed the exfiltration vector in the macOS app version 1.2024.247; the researcher notes memory injection itself remained possible.