We've said it before,as eroticism revels in the rotting stench of deathand we'll sayit again: Don't input anything into ChatGPT that you don't want unauthorized parties to read.
Since OpenAI released ChatGPT last year, there have been quite a few occasions where flaws in the AI chatbot could've been weaponized or manipulated by bad actors to access sensitive or private data. And this latest example shows that even after a security patch has been released, problems can still persist.
According to a report by Bleeping Computer, OpenAI has recently rolled out a fix for an issue where ChatGPT could leak users' data to unauthorized third parties. This data could include user conversations with ChatGPT and corresponding metadata like a user's ID and session information.
However, according to security researcher Johann Rehberger, who originally discovered the vulnerability and outlined how it worked, there are still gaping security holes in OpenAI's fix. In essence, the security flaw still exists.
Rehberger was able to take advantage of OpenAI's recently released and much-lauded custom GPTsfeature to create his own GPT, which exfiltrated data from ChatGPT. This was a significant finding as custom GPTs are being marketed as AI apps akin to how the iPhone revolutionized mobile applications with the App Store. If Rehberger could create this custom GPT, it seems like bad actors could soon discover the flaw and create custom GPTs to steal data from their targets.
Rehberger says he first contactedOpenAI about the "data exfiltration technique" way back in April. He contacted OpenAI once again in November to report exactly how he was able to create a custom GPT and carry out the process.
On Wednesday, Rehberger posted an updateto his website. OpenAI had patched the leak vulnerability.
"The fix is not perfect, but a step into the right direction," Rehberger explained.
The reason the fix isn't perfect is that ChatGPT is still leaking data through the vulnerability Rehberger discovered. ChatGPT can still be tricked into sending data.
"Some quick tests show that bits of info can steal [sic] leak," Rehberger wrote, further explaining that "it only leaks small amounts this way, is slow and more noticeable to a user." Regardless of the remaining issues, Rehberger said it's a "step in the right direction for sure."
But, the security flaw still remains entirely in the ChatGPT apps for iOS and Android, which have yet to be updated with a fix.
ChatGPT users should remain vigilant when using custom GPTs and should likely pass on these AI apps from unknown third parties.
Topics Artificial Intelligence Cybersecurity ChatGPT OpenAI
Congratulations, 2019 was the second hottest year on recordTwitter hails 'braveheart' mother who jumped on a leopard to save her sonUh, you should really update Firefox. Like, right now.Apple will replace some iPhone batteries for freeThe best signs from Australia's climate protests amid bushfire crisisReddit bests Facebook by rolling out a superior deepfakes policyReddit bests Facebook by rolling out a superior deepfakes policyHow to help mental health efforts following Puerto Rico earthquakeIndia's biggest online retailer is acquiring eBay's India business, report saysLizzo lends a hand packing hampers for people affected by Australia's bushfire crisisGeneral Motors revamping Hummer as an electric pickup truck by 2022'The Crown' won't cover Prince Harry & Meghan Markle's latest developmentsCongratulations, 2019 was the second hottest year on recordSamsung reveals how many Galaxy Fold phones it really sold, sort ofCritics who called out Chelsea Clinton for 'Lifetime Impact Award' made one large errorJustin Bieber suggested fans boost 'Yummy' by cheating music charts with VPNsThe most insightful vision of the future at CES came from HBO's 'Westworld'These powerful London Underground signs are going viralDid you know you shouldn't feed ducks bread? These people didn't.Instagram just launched new TikTok — ahem, Boomerang — effects The 8 'Counter This bag of chips can sense if you've been drinking and call you an Uber Google Maps is getting better at helping you avoid crowds New leaked Galaxy S8 photos finally reveal its headphone jack status British women pen emotional letters to Theresa May before she meets Trump Facebook is giving longer videos a bump in your News Feed Fighting game community is in a heated debate over teabagging Google purges nearly 200 websites in fake news crackdown Shia LaBeouf arrested during anti There are hidden iPad keyboards in iOS 10.3 that Apple won't let you use Trump capping a pen with his tiny hands gets a huge Photoshop battle Yes, really: '1984' is now sold out on Amazon Twitter no longer recommends Trump's profile when you search 'asshole' Bernie Sanders' digital team offers a way for people to call the White House Trump's POTUS Twitter account security faces questions Engineers outfit dragonflies with hybrid drone tech Train crashes into a FedEx truck and sends packages flying Please leave me alone while I stare at this photo of Jupiter Bride perfectly trolls her groom in a ridiculous T That kid who said 'screw our president' is apparently Drew Carey's son
3.6812s , 10192.1015625 kb
Copyright © 2025 Powered by 【as eroticism revels in the rotting stench of death】,Exquisite Information Network