OpenAI has patched a flaw that could have allowed hackers to manipulate ChatGPT into leaking private information from a victim’s Gmail inbox.
Cybersecurity vendor Radware discovered and reported the vulnerability, according to Bloomberg. The problem involved ChatGPT’s "deep research" function, which can handle more complex tasks, including browsing the web and analyzing messages and files in your inbox.
With your permission, deep research can connect to Gmail, Google Drive, Microsoft’s OneDrive, and a variety of other apps. The vulnerability arises if a user asks ChatGPT to perform a deep research-related query on their Gmail inbox. Radware found ChatGPT could be manipulated into scanning and leaking the user’s private information if it encounters a hacker-written email containing secret instructions to tamper with the chatbot.
The proof-of-concept attack wasn’t easy to develop and execute. Radware said, “This process was a rollercoaster of failed attempts, frustrating roadblocks...
Tags, Events, and Projects