Johann Rehberger showed that prompt injection from a web page or document could write attacker instructions into ChatGPT's long-term memory, which then persisted into later conversations and exfiltrated what the user typed. OpenAI fixed the exfiltration vector in the macOS app version 1.2024.247; the researcher notes memory injection itself remained possible.
Why it matters
Persistent memory turns a one-time injection into a durable compromise across sessions.
Key facts
As stated in the sources, with where to find them.
- Fix shipped in ChatGPT macOS version 1.2024.247 in September 2024.OpenAI response section
- The researcher states only the exfiltration vector was mitigated, not memory injection.OpenAI response section
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Feb 13, 2026
Jan 28, 2026
Aug 6, 2025
Aug 20, 2024
Nov 3, 2023
Mar 5, 2024