CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Persistent Memory Exploit in ChatGPT Atlas Browser

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A vulnerability in the ChatGPT Atlas browser allows attackers to inject persistent, hidden commands into the AI's memory. This exploit leverages a CSRF flaw to plant malicious instructions that persist across devices and sessions, enabling unauthorized code execution and potential data exfiltration. The vulnerability affects the browser's memory feature, which stores user preferences and details to personalize interactions. The exploit can lead to account takeovers, privilege escalation, and malware deployment. Users are at risk when they interact with ChatGPT after being tricked into visiting a malicious link. The attack vector is exacerbated by the browser's lack of robust anti-phishing controls, making users significantly more vulnerable compared to traditional browsers. The vulnerability highlights the security risks associated with AI-powered browsers and the need for enhanced protections as these tools become more integrated into enterprise environments.

Timeline

  1. 27.10.2025 16:31 1 articles · 23h ago

    Persistent Memory Exploit Discovered in ChatGPT Atlas Browser

    A new vulnerability in the ChatGPT Atlas browser allows attackers to inject persistent, hidden commands into the AI's memory. This exploit leverages a CSRF flaw to plant malicious instructions that persist across devices and sessions, enabling unauthorized code execution and potential data exfiltration. The vulnerability affects the browser's memory feature, which stores user preferences and details to personalize interactions. The exploit can lead to account takeovers, privilege escalation, and malware deployment. Users are at risk when they interact with ChatGPT after being tricked into visiting a malicious link. The attack vector is exacerbated by the browser's lack of robust anti-phishing controls, making users significantly more vulnerable compared to traditional browsers.

    Show sources

Information Snippets