
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Researchers discovered critical vulnerabilities in Lenovo's GPT-4-powered customer service chatbot, Lena, allowing attackers to exploit prompt injection and XSS flaws. These weaknesses enabled theft of session cookies, execution of malicious code, and potential unauthorized access to corporate systems. Lenovo has since patched the flaw, but the incident highlights significant AI security risks.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Lenovo's chatbot powered by GPT-4) whose use and malfunction (due to poor input/output sanitization and prompt injection vulnerabilities) directly led to security breaches that could cause harm to property, communities, and potentially violate privacy and security rights. The chatbot's outputs enabled attackers to steal session cookies and potentially execute remote code, which constitutes a direct AI Incident as defined by the framework. The harm is realized (or at least the vulnerability is actively exploitable), and the incident has significant security implications. Therefore, this is classified as an AI Incident.[AI generated]