HomeSecurity7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

Seven critical vulnerabilities in OpenAI's ChatGPT, affecting both GPT-4o and the newly released GPT-5 models, could allow attackers to steal private user data through invisible, zero-interaction exploits.

See also: XLoader malware analyzed with the help of ChatGPT

GPT-4 or GPT-5
7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

These security vulnerabilities exploit indirect prompt injections, allowing hackers to manipulate AI technology to extract sensitive information from user memories and chat histories without any user interaction beyond a simple question.

With hundreds of millions of daily users relying on large language models like ChatGPT, this discovery highlights the urgent need for stronger AI safeguards in an era where LLMs are becoming primary sources of information.

The vulnerabilities stem from ChatGPT’s core architecture, which relies on systemic prompts, memory tools, and web browsing capabilities to provide context-based responses. OpenAI’s systemic prompt defines the model’s capabilities, including a “bio” tool for long-term user memories that is enabled by default, and a “web” tool for accessing the web via search or URL browsing.

Memories can store private details deemed important from past conversations, while the web tool uses a secondary AI, SearchGPT, to isolate browsing from the user's context, theoretically preventing data leaks.

See also: OpenAI: Aardvark detects errors in code

7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

However, Tenable researchers found that SearchGPT's isolation is insufficient, allowing prompt injections to propagate back to ChatGPT.

Among the seven vulnerabilities, the indirect zero-interaction prompt injection in the search context stands out, where attackers create indexed web pages tailored to trigger searches on specialized topics.

Tenable demonstrated complete attack chains, such as phishing via blog comments leading to malicious links or markdown images that extract information using url_safe.

In proofs of concept for GPT-4o and GPT-5, attackers phished users by summarizing fake blogs or hijacking search results to insert persistent memories that continuously leak data. These scenarios highlight how everyday tasks like searching for dinner ideas could inadvertently expose personal details.

See also: ChatGPT Atlas can be fooled by fake URLs

7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

Tenable disclosed the issues to OpenAI, which resulted in some vulnerabilities being patched via Technical Research Advisory (TRAs) such as TRA-2025-22, TRA-2025-11, and TRA-2025-06. Despite the improvements, prompt injection remains an inherent risk in large language models.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS