HomeSecurityResearchers trick ChatGPT into inserting prompts into itself

Researchers trick ChatGPT into inserting prompts into itself

AI chatbots have opened a new front of attack against users and their data, and even industry leaders are not immune. After recent bugs discovered in Google's Gemini and Anthropic's Claude, now it's ChatGPT's turn.

See also: XLoader malware analyzed with the help of ChatGPT

ChatGPT prompts

Researchers from security firm Tenable have discovered seven ways attackers could trick ChatGPT into revealing private information from users’ chat histories. Most of these attacks are indirect prompt injections that exploit the default tools and features that OpenAI provides to ChatGPT, including its ability to remember the context of the conversation over the long term and its web search capabilities.

ChatGPT can search the web for information and visit user-provided URLs to extract content on request. However, this content is not passed directly to ChatGPT. Instead, it passes through an intermediate, more limited large language model (LLM) called SearchGPT, which then summarizes the content for ChatGPT. The use of a secondary model that does not have direct access to the user's chat appears to be an architectural decision specifically aimed at limiting the impact of potential prompt injection attacks from web content.

Tenable researchers found that SearchGPT is indeed vulnerable to prompt injections when parsing web pages during either browsing or search operations. Attackers could, for example, place malicious prompts in blog comments or create a poisoned web page that ranks high in search results for specific keywords — ChatGPT uses Bing for search, the researchers discovered.

See also: 7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

Researchers trick ChatGPT into inserting prompts into itself

Additionally, to hide malicious prompts, attackers could present a clean version of a web page to search engines and regular visitors, while serving a different version to OpenAI's web crawlers, which are identified by a User-Agent string called OAI-Search in request headers.

However, even if an attacker manages to get SearchGPT to execute a malicious prompt, the separation of its context from ChatGPT means that the model does not have direct access to private user information. Nevertheless, the researchers found a way to exploit the relationship between the two models.

Because ChatGPT receives output from SearchGPT after the search model has processed the content, Tenable researchers wondered what would happen if SearchGPT's response itself contained a prompt injection. In other words, could they use a web page to inject a prompt that instructs SearchGPT to inject a different prompt into ChatGPT, essentially creating a chain attack? The answer is yes.

“Prompt injection is a known problem with the way LLMs work and unfortunately, it will likely not be systematically resolved in the near future,” the researchers wrote. “AI vendors should ensure that all their security mechanisms (such as url_safe) are working properly to limit the potential damage caused by prompt injection.”

See also: OpenAI: Aardvark detects errors in code

Researchers trick ChatGPT into inserting prompts into itself

Tenable reported its findings to OpenAI, and while some fixes have been implemented, some techniques still work. Tenable's research began in 2024 and was primarily conducted on GPT-4, but the researchers confirmed that GPT-5 is also vulnerable to some of these attack methods.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS