ZombieAgent Vulnerability Enables Data Theft and Account Takeover in ChatGPT

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Radware researchers discovered a zero-click vulnerability, dubbed ZombieAgent, affecting OpenAI's ChatGPT and Deep Research agents. Exploiting new features like memory and connectors, attackers could silently exfiltrate user data, hijack accounts, and maintain persistent access. OpenAI patched the vulnerability in December 2025, but incidents of data theft had already occurred.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly involves an AI system (ChatGPT) and details how its vulnerabilities have been exploited to steal private user information, constituting harm to individuals' privacy and rights. The attack is a direct consequence of the AI system's design and operation, fulfilling the criteria for an AI Incident. The harm is realized, not just potential, as data exfiltration has occurred. The ongoing cycle of attack and mitigation further underscores the incident nature rather than a mere hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securitySafety

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Business function:
Citizen/customer service

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard