ChatGPT Connectors Vulnerability Enables Zero-Click Data Theft via Poisoned Documents

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Security researchers demonstrated that a vulnerability in OpenAI's ChatGPT Connectors allows attackers to steal sensitive data from linked services like Google Drive using a single 'poisoned' document. The attack, requiring no user interaction, exploits indirect prompt injection, leading to unauthorized data access and privacy breaches.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (ChatGPT with Connectors integration) whose use was exploited to cause harm by enabling unauthorized access to sensitive data stored in Google Drive. The exploit could have led to direct harm to individuals' data privacy and security, fulfilling the criteria for an AI Incident. Although OpenAI mitigated the issue after disclosure, the exploit was demonstrated and could have been used maliciously, indicating realized harm or at least a concrete incident of AI misuse leading to harm.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRespect of human rightsRobustness & digital securitySafety

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Business function:
ICT management and information security

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard