| |
ChatGPT for Google Sheets Exfiltrates Workbooks
A vulnerability in OpenAI's ChatGPT for Google Sheets extension allows attackers to exfiltrate workbooks, display phishing pop-ups, and hijack the chatbot interface through indirect prompt injection attacks—bypassing even explicit human approval settings. The attack works by embedding hidden prompts in external data sources that manipulate ChatGPT into executing attacker-controlled scripts with the permissions granted to the extension. OpenAI has since disabled the extension's ability to generate Apps Script code to mitigate the risk.
Read Full Article →
← More Tech news