ChatGPT for Google Sheets Exfiltrates User Data via Prompt Injection

TL;DR. ChatGPT for Google Sheets contains a critical vulnerability, allowing data exfiltration and phishing through indirect prompt injection. - A single malicious Google Sheet can trigger unauthorized actions even with approval settings enabled. - The vulnerability exploits an attacker-controlled script running with the extension's user permissions. - OpenAI was responsibly notified but did not acknowledge the security flaw or provide a fix.

Sources

Back to QLANKR News