ChatGPT/SearchGPT prompt injection and data exfiltration weaknesses security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Researchers uncovered seven weaknesses in OpenAI's ChatGPT/SearchGPT that could let an attacker use prompt injection and safety bypass techniques to steal private chat history and stored memories. The flaws affect how the system browses the web, opens URLs, and processes external content, widening the attack surface for users who rely on it for search and summarization. Researchers said the issues can be chained into complete attack paths, making the privacy risk materially more serious than a single isolated bug. The findings were disclosed to OpenAI in April and were reported publicly on 2025-11-06.
Related Happenings
OpenClaw message-object prompt injection patched in 2026.4.23 security flaw
Vulnerability
H score15
First: 11.06.2026 20:46
Last: 11.06.2026 20:46
Sources 1
About this happening:
**OpenClaw** has a patched **message-object prompt injection flaw** that let hidden instructions inside **shared contacts, vCards, and location pins** reach the LLM as trusted pro...
OpenClaw message-object prompt injection patched in 2026.4.23 security flaw
VulnerabilityAbout this happening: **OpenClaw** has a patched **message-object prompt injection flaw** that let hidden instructions inside **shared contacts, vCards, and location pins** reach the LLM as trusted pro...
OpenAI ChatGPT Lockdown Mode rollout limits prompt-injection exfiltration paths
Security Tool/Service
H score10
First: 06.06.2026 16:36
Last: 06.06.2026 16:36
Sources 1
About this happening:
**OpenAI ChatGPT** is rolling out **Lockdown Mode** for eligible personal accounts, reducing the risk of **prompt-injection-driven data exfiltration**. The update adds stricter li...
OpenAI ChatGPT Lockdown Mode rollout limits prompt-injection exfiltration paths
Security Tool/ServiceAbout this happening: **OpenAI ChatGPT** is rolling out **Lockdown Mode** for eligible personal accounts, reducing the risk of **prompt-injection-driven data exfiltration**. The update adds stricter li...
OpenAI ChatGPT renderer Markdown link/image phishing security flaw
Vulnerability
H score16
First: 29.05.2026 21:07
Last: 29.05.2026 21:07
Sources 1
About this happening:
**ChatGPT** has a **response-renderer vulnerability** that turns summarized third-party pages into **live phishing links** and auto-fetched **attacker-hosted images** inside the t...
OpenAI ChatGPT renderer Markdown link/image phishing security flaw
VulnerabilityAbout this happening: **ChatGPT** has a **response-renderer vulnerability** that turns summarized third-party pages into **live phishing links** and auto-fetched **attacker-hosted images** inside the t...
ChatGPT single-prompt DNS side-channel exfiltration remote code execution flaw
Vulnerability
H score36
First: 31.03.2026 16:01
Last: 31.03.2026 16:01
Sources 1
About this happening:
A **ChatGPT** vulnerability let a **single malicious prompt** covertly exfiltrate prompts, messages, uploaded files, and other sensitive content through a **DNS side channel**. Th...
ChatGPT single-prompt DNS side-channel exfiltration remote code execution flaw
VulnerabilityAbout this happening: A **ChatGPT** vulnerability let a **single malicious prompt** covertly exfiltrate prompts, messages, uploaded files, and other sensitive content through a **DNS side channel**. Th...
OpenAI Safety Bug Bounty launch
Commercial Activity
H score0
First: 26.03.2026 14:20
Last: 26.03.2026 14:20
Sources 1
About this happening:
**OpenAI** launched the **Safety Bug Bounty** on **Bugcrowd**, expanding researcher coverage for **AI abuse** and **safety risks** across its products. The new program complements...
OpenAI Safety Bug Bounty launch
Commercial ActivityAbout this happening: **OpenAI** launched the **Safety Bug Bounty** on **Bugcrowd**, expanding researcher coverage for **AI abuse** and **safety risks** across its products. The new program complements...
Timeline
-
06.11.2025 12:00 2 articles · 7mo ago
Tenable discloses seven ChatGPT/SearchGPT weaknesses
Initial DisclosureResearchers disclosed seven weaknesses in OpenAI's ChatGPT and SearchGPT that can be chained to exfiltrate private information from a user's chat history and stored memories, using indirect prompt injection, crafted chat URLs such as https://chatgpt.com/?q={Prompt}, poisoned search results, blog comments, and Bing tracking links to bypass safety filters and sustain access; the issues were reported to OpenAI in April and publicly described on 2025-11-06.
Show sources
- Multiple ChatGPT Security Bugs Allow Rampant Data Theft — www.darkreading.com — 06.11.2025 12:00
- Multiple ChatGPT Security Bugs Allow Rampant Data Theft — www.darkreading.com — 06.11.2025 12:00