HomeSecurityOpenAI: Solution to the data leak problem in ChatGPT

OpenAI: Solution to the data leak problem in ChatGPT

OpenAI has fixed a serious data leak issue in ChatGPT that could leak chat details to an external URL. According to the researcher who discovered the flaw, the workaround is not perfect, so attackers can still exploit the opportunity under certain circumstances.

See also: ChatGPT: Back online after a major outage
OpenAI

Additionally, security checks have not yet been implemented in the iOS for ChatGPT, so the risk on this platform remains.

Security researcher Johann Rehberger discovered a technique for recovering ChatGPT data and reported it to OpenAI in April 2023. The researcher later shared additional information in November 2023 about creating malicious GPTs that exploit the flaw to gain access to users via phishing.

“This GPT and corresponding instructions were directly reported to OpenAI on November 13, 2023,” the researcher wrote in this statement.

“However, the ticket was closed on November 15th as “Not Applicable”. Two more inquiries remained unanswered. Therefore, it seems best to share this with the public for awareness.“

GPTs are personalized AI models promoted as “AI applications,” specializing in various roles, such as customer support agents, writing and translation assistants, performing data analysis, creating cooking recipes based on available ingredients, collecting data for research, and even playing games.

See also: ChatGPT comes to Microsoft Word via Ghostwriter add-in

After a lack of response from the chatbot vendor, the researcher decided to publicly disclose his findings on December 12, 2023. During the presentation, he showed a customized GPT for the tic-tac-toe game called “The Thief!”, which can transfer data to an external URL operated by the researcher.

ChatGPT

Data theft involves displaying images marked with destruction and inserting prompts, so the attack requires the victim to submit a malicious prompt that the attacker provides directly or posts somewhere for victims to discover and use.

Alternatively, a malicious GPT can be used, as demonstrated by Rehberger, and users using this GPT will not realize that their conversation details, along with metadata (timestamps, user ID, session ID) and technical data (IP address, trigger strings) are being leaked to third parties.

After Rehberger published the details of the bug on his website, OpenAI responded to the situation and implemented client via a call to a validation API to prevent images from being displayed from unsafe URLs.

To protect your personal data, it is important to use strong and unique passwords for each of your accounts. This can help prevent unwanted users from accessing your data.

See also: ChatGPT: It accurately recognizes emotions much better than humans

Additionally, it's important to keep software and operating system up to date. Updates often include security patches that can protect your data from new threats. Another important strategy is to use VPNs when connecting to the internet from public Wi-Fi. VPNs can encrypt your data, making it unreadable to attackers.

Also, be careful about the information you share on social media. Information that seems harmless, like your date of birth or address, can be used by attackers to hack into your accounts.

Finally, it's wise to use identity protection services or regularly monitor your credit reports to spot any suspicious activity.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS