Chronicle/Attacks & incidents

ChatGPT macOS memory could be poisoned by prompt injection for persistent data exfiltration

AttackVulnerability disclosureSignificance assistant-drafted

Johann Rehberger showed that prompt injection from a web page or document could write attacker instructions into ChatGPT's long-term memory, which then persisted into later conversations and exfiltrated what the user typed. OpenAI fixed the exfiltration vector in the macOS app version 1.2024.247; the researcher notes memory injection itself remained possible.

Why it matters

Persistent memory turns a one-time injection into a durable compromise across sessions.

Key facts

As stated in the sources, with where to find them.

  • Fix shipped in ChatGPT macOS version 1.2024.247 in September 2024.OpenAI response section
  • The researcher states only the exfiltration vector was mitigated, not memory injection.OpenAI response section

Findings that cite this record

Key questions this bears on

Sources

Related records