Seven critical vulnerabilities in OpenAI's ChatGPT, affecting both GPT-4o and the newly released GPT-5 models, could allow attackers to steal private user data through invisible, zero-interaction exploits.
See also: XLoader malware analyzed with the help of ChatGPT

These security vulnerabilities exploit indirect prompt injections, allowing hackers to manipulate AI technology to extract sensitive information from user memories and chat histories without any user interaction beyond a simple question.
With hundreds of millions of daily users relying on large language models like ChatGPT, this discovery highlights the urgent need for stronger AI safeguards in an era where LLMs are becoming primary sources of information.
The vulnerabilities stem from ChatGPT’s core architecture, which relies on systemic prompts, memory tools, and web browsing capabilities to provide context-based responses. OpenAI’s systemic prompt defines the model’s capabilities, including a “bio” tool for long-term user memories that is enabled by default, and a “web” tool for accessing the web via search or URL browsing.
Memories can store private details deemed important from past conversations, while the web tool uses a secondary AI, SearchGPT, to isolate browsing from the user's context, theoretically preventing data leaks.
See also: OpenAI: Aardvark detects errors in code

However, Tenable researchers found that SearchGPT's isolation is insufficient, allowing prompt injections to propagate back to ChatGPT.
Among the seven vulnerabilities, the indirect zero-interaction prompt injection in the search context stands out, where attackers create indexed web pages tailored to trigger searches on specialized topics.
Tenable demonstrated complete attack chains, such as phishing via blog comments leading to malicious links or markdown images that extract information using url_safe.
In proofs of concept for GPT-4o and GPT-5, attackers phished users by summarizing fake blogs or hijacking search results to insert persistent memories that continuously leak data. These scenarios highlight how everyday tasks like searching for dinner ideas could inadvertently expose personal details.
See also: ChatGPT Atlas can be fooled by fake URLs

Tenable disclosed the issues to OpenAI, which resulted in some vulnerabilities being patched via Technical Research Advisory (TRAs) such as TRA-2025-22, TRA-2025-11, and TRA-2025-06. Despite the improvements, prompt injection remains an inherent risk in large language models.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
