We've said it before,and we'll sayit again: Don't input anything into ChatGPT that you don't want unauthorized parties to read.
Since OpenAI released ChatGPT last year, there have been quite a few occasions where flaws in the AI chatbot could've been weaponized or manipulated by bad actors to access sensitive or private data. And this latest example shows that even after a security patch has been released, problems can still persist.
According to a report by Bleeping Computer, OpenAI has recently rolled out a fix for an issue where ChatGPT could leak users' data to unauthorized third parties. This data could include user conversations with ChatGPT and corresponding metadata like a user's ID and session information.
However, according to security researcher Johann Rehberger, who originally discovered the vulnerability and outlined how it worked, there are still gaping security holes in OpenAI's fix. In essence, the security flaw still exists.
Rehberger was able to take advantage of OpenAI's recently released and much-lauded custom GPTsfeature to create his own GPT, which exfiltrated data from ChatGPT. This was a significant finding as custom GPTs are being marketed as AI apps akin to how the iPhone revolutionized mobile applications with the App Store. If Rehberger could create this custom GPT, it seems like bad actors could soon discover the flaw and create custom GPTs to steal data from their targets.
Rehberger says he first contactedOpenAI about the "data exfiltration technique" way back in April. He contacted OpenAI once again in November to report exactly how he was able to create a custom GPT and carry out the process.
On Wednesday, Rehberger posted an updateto his website. OpenAI had patched the leak vulnerability.
"The fix is not perfect, but a step into the right direction," Rehberger explained.
The reason the fix isn't perfect is that ChatGPT is still leaking data through the vulnerability Rehberger discovered. ChatGPT can still be tricked into sending data.
"Some quick tests show that bits of info can steal [sic] leak," Rehberger wrote, further explaining that "it only leaks small amounts this way, is slow and more noticeable to a user." Regardless of the remaining issues, Rehberger said it's a "step in the right direction for sure."
But, the security flaw still remains entirely in the ChatGPT apps for iOS and Android, which have yet to be updated with a fix.
ChatGPT users should remain vigilant when using custom GPTs and should likely pass on these AI apps from unknown third parties.
Copyright © 2023 Powered by
OpenAI releases ChatGPT data leak patch, but the issue isn't completely fixed-声闻过情网
sitemap
文章
63693
浏览
6
获赞
639
The new MacBook Air and MacBook Pro are powered by Apple's own M1 chip
Apple has officially unveiled two new pieces of hardware: the MacBook Air and MacBook Pro. Both MacBNASA asked for cheaper ways to get Mars samples. It had one all along.
NASAwill investigate two new approaches to bring its Mars samples to Earth through a mission proposaSpace calendar 2025: Here are the moments you won't want to miss
Though 2025 won't mark the return of astronautsinto deep spaceas NASAhad hoped, launchpads still wilEssential Apps to Install on your Windows PC or Mac
You just bought a new laptop, built a new desktop PC, or are simply clean installing on a new solidTrump complains about flushing, becomes the butt of Twitter jokes
The president made a bizarre claim that people flush their toilets "10 times, 15 times" per visit, aApple adds Business Chat to iMessage to take on Facebook
Apple's iMessage isn't just for talking to your friends, anymore.Today Apple officially rolled out iThe Zero Click Internet
The internet is in the midst of undergoing the biggest change since its inception. It's huge. And thBest Samsung TV deal: Save $1,700 on Samsung S84D 4K OLED TV
SAVE $1,700:As of Jan. 7, Samsung's 77-inch S84D 4K OLED Smart TV is on sale at Best Buy for $1,599.Xiaomi Mi 10T Pro has a 144Hz display, 5,000mAh battery
Xiaomi's flagship phones have been following the same pattern for years: Low price, top specs, few cGoogle brings back digital fingerprinting to track users for advertising
Google is tracking your online behavior in the name of advertising, reintroducing a data collectionUber drivers could be employees... in Brazil
Uber drivers just won a major victory — but only in Brazil. A judge in Sao Paulo ruled that aMum says what everyone's thinking about prams being used as a status symbol
A mother of one from Cornwall, UK, has hit out at the world of "pram snobbery" and the pressure to bThe $80,000 Lucid Air: It'll be nice when we can drive it
Lucid they may be, but they're not exactly transparent. The buzzworthy Bay Area car company, which mWhich iPad Model Should You Get?
Thanks to class-leading hardware and optimized software, the Apple iPad line has long been the go-toU.S. satellites reveal China's solar dominance
The sun's energy is plentiful. And China is capitalizing. Images captured by two Earth-observing sat