OpenAI Faces New Vulnerabilities in ChatGPT Prompt Injection Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Radware’s security researchers uncovered several vulnerabilities in OpenAI’s ChatGPT service, specifically related to prompt injection attacks. The initial report was filed on September 26, 2025, and OpenAI attempted to address these issues, including a patch for the ShadowLeak vulnerability on September 3, 2025. ShadowLeak allowed malicious prompts to be executed through content stored in systems linked to ChatGPT, such as Gmail and Google Drive.
The ShadowLeak vulnerability enabled attackers to manipulate ChatGPT into executing harmful actions, like transmitting sensitive data without user intervention. OpenAI’s fix involved restricting URL modifications, but this was insufficient, as attackers developed a new method called ZombieAgent. This method exfiltrates data character by character using static URLs, bypassing the security measures implemented by OpenAI.
ZombieAgent also takes advantage of ChatGPT’s memory feature, allowing attackers to issue commands that can modify stored information. For instance, an attacker could instruct ChatGPT to read their emails and execute specific actions based on that content. This capability poses a significant risk, as it could lead to the dissemination of incorrect medical advice or the unauthorized sharing of sensitive user data.
Pascal Geenens from Radware highlighted the broader implications of these vulnerabilities, emphasizing that enterprises rely on AI agents for critical decisions but lack visibility into how these agents interpret untrusted content. This gap in security creates a dangerous environment where attackers can exploit AI platforms.
Implications for Users and Organizations
These vulnerabilities underscore the need for heightened awareness regarding the security of AI systems. Users should be cautious about the information they share with AI platforms, especially in contexts where sensitive data is involved. Organizations must also evaluate their reliance on AI agents and ensure they have robust security measures in place to monitor and control how these agents interact with external content.
As AI technologies continue to evolve, understanding the potential risks associated with prompt injection attacks and the manipulation of AI memory features will be crucial for maintaining cybersecurity. Regular audits and updates to security protocols can help mitigate these risks and protect sensitive information from exploitation.
Key Takeaways
- Be cautious when sharing sensitive information with AI platforms like ChatGPT.
- Regularly review and update security protocols related to AI systems in your organization.
- Monitor interactions with AI agents to ensure they are not executing unauthorized actions.
- Educate users about the risks of prompt injection attacks and how to recognize suspicious activity.
- Consider implementing additional security measures to safeguard against data exfiltration through AI systems.
Key Terms & Concepts
- ShadowLeak: In this article, ShadowLeak refers to a vulnerability in ChatGPT that allows indirect prompt injection attacks.
- ZombieAgent: ZombieAgent is a new attack method that exfiltrates data from ChatGPT one character at a time using static URLs.
- prompt injection: Prompt injection is a technique where attackers manipulate AI models into executing harmful commands through crafted inputs.
- memory feature: ChatGPT’s memory feature allows it to store and recall information across sessions, which can be exploited by attackers.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.