ChatGPT blind trust allows prompt injection through web content

TL;DR. ChatGPT's inability to distinguish its own content from external, attacker-controlled data creates a critical prompt injection vulnerability. - Attackers can insert phishing URLs or fake security alerts into ChatGPT responses. - Exploits can bypass desktop security by using in-line QR codes linking to S3 buckets. - OpenAI allegedly marked the reported flaw as not reproducible or a duplicate.

Sources

Back to QLANKR News