ChatGPT blind trust allows prompt injection through web content
TL;DR. ChatGPT's inability to distinguish its own content from external, attacker-controlled data creates a critical prompt injection vulnerability. - Attackers can insert phishing URLs or fake security alerts into ChatGPT responses. - Exploits can bypass desktop security by using in-line QR codes linking to S3 buckets. - OpenAI allegedly marked the reported flaw as not reproducible or a duplicate.
- ChatGPT is vulnerable to prompt injection attacks via external web content.
- The flaw allows attackers to inject malicious content like phishing links or fake alerts.
- Attackers can use QR codes to pivot attacks to mobile, bypassing desktop defenses.
- OpenAI has reportedly not confirmed a fix for the discovered vulnerability.
Sources
- ChatGPT blindly trusts browser content, turning the page into a payload — theregister.com
- prezlo.io — prezlo.io
- thehackernews.com — thehackernews.com