ChatGPT security flaw raises concerns over private data
The latest findings from Check Point Research serve as a wake-up call for organizations increasingly relying on AI tools. Researchers uncovered a technique that could allow hidden interactions between ChatGPT accounts, potentially enabling attackers to misuse a victim's session without their awareness. The discovery reinforces a critical lesson that “as AI capabilities expand, safeguarding user…
Researchers have discovered a security flaw in ChatGPT that could allow attackers to secretly communicate between user sessions without the victim's knowledge. This vulnerability could enable unauthorized access to a victim's account, sensitive data, and connected services. The flaw exploits the internal service used to provide software packages, which could act as a secret messaging route between accounts.
An attacker could potentially retrieve information from a victim's connected Gmail account and send it back to an attacker-controlled ChatGPT account. The attack could be initiated through a malicious prompt, shared conversation, or custom GPT. Users should be cautious about what they connect to AI services and avoid granting unnecessary access to AI assistants.
Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.