ChatGPT for Google Sheets Exfiltrates User Data via Prompt Injection
TL;DR. ChatGPT for Google Sheets contains a critical vulnerability, allowing data exfiltration and phishing through indirect prompt injection. - A single malicious Google Sheet can trigger unauthorized actions even with approval settings enabled. - The vulnerability exploits an attacker-controlled script running with the extension's user permissions. - OpenAI was responsibly notified but did not acknowledge the security flaw or provide a fix.
- ChatGPT for Google Sheets is vulnerable to indirect prompt injection attacks.
- The vulnerability allows exfiltration of multiple workbooks and display of phishing pop-ups.
- Attacker-controlled scripts can execute even when manual approval settings are configured.
- OpenAI did not respond to responsible disclosure of the vulnerability.
Sources
- ChatGPT for Google Sheets Exfiltrates Workbooks — promptarmor.com