We've said it before,and we'll sayit again: Don't input anything into ChatGPT that you don't want unauthorized parties to read.
Since OpenAI released ChatGPT last year, there have been quite a few occasions where flaws in the AI chatbot could've been weaponized or manipulated by bad actors to access sensitive or private data. And this latest example shows that even after a security patch has been released, problems can still persist.
According to a report by Bleeping Computer, OpenAI has recently rolled out a fix for an issue where ChatGPT could leak users' data to unauthorized third parties. This data could include user conversations with ChatGPT and corresponding metadata like a user's ID and session information.
However, according to security researcher Johann Rehberger, who originally discovered the vulnerability and outlined how it worked, there are still gaping security holes in OpenAI's fix. In essence, the security flaw still exists.
Rehberger was able to take advantage of OpenAI's recently released and much-lauded custom GPTsfeature to create his own GPT, which exfiltrated data from ChatGPT. This was a significant finding as custom GPTs are being marketed as AI apps akin to how the iPhone revolutionized mobile applications with the App Store. If Rehberger could create this custom GPT, it seems like bad actors could soon discover the flaw and create custom GPTs to steal data from their targets.
Rehberger says he first contactedOpenAI about the "data exfiltration technique" way back in April. He contacted OpenAI once again in November to report exactly how he was able to create a custom GPT and carry out the process.
On Wednesday, Rehberger posted an updateto his website. OpenAI had patched the leak vulnerability.
"The fix is not perfect, but a step into the right direction," Rehberger explained.
The reason the fix isn't perfect is that ChatGPT is still leaking data through the vulnerability Rehberger discovered. ChatGPT can still be tricked into sending data.
"Some quick tests show that bits of info can steal [sic] leak," Rehberger wrote, further explaining that "it only leaks small amounts this way, is slow and more noticeable to a user." Regardless of the remaining issues, Rehberger said it's a "step in the right direction for sure."
But, the security flaw still remains entirely in the ChatGPT apps for iOS and Android, which have yet to be updated with a fix.
ChatGPT users should remain vigilant when using custom GPTs and should likely pass on these AI apps from unknown third parties.
Copyright © 2023 Powered by
OpenAI releases ChatGPT data leak patch, but the issue isn't completely fixed-拍板定案网
sitemap
文章
8986
浏览
94678
获赞
9858
These coronavirus trackers can help you sort through the info overload
If you're like me, the daily barrage of information about the progress of the coronavirus pandemic cTikTok's first book awards: Check out the shortlist
TikTok's book-loving community, officially known as #BookTok, is a force. With over 157 billion viewHow to change Siri's voice in iOS 14.5
If you're tired of hearing Siri's default voice, you're in luck. With iOS and iPadOS 14.5, you haveGoogle IO 2021: Android phones get Android TV remote functionality
We've all been there: You need to sign into Netflix, Disney+, HBO Max, or any other streaming servicGoogle says no to Zoom
Zoom, the videoconferencing software that people seem to alternately love and hate these days, is no13 amazing holiday gifts for the person who already has it all
This holiday season, don’t be daunted by the challenge of shopping for that friend or family mGoogle wants to make changing your compromised passwords easier
If you won't clean up your compromised passwords, then Google, like an exasperated parent, will haveMeet Carrie Bradshaw's biggest critic
Carrie Bradshaw is, arguably, one of the most distinguishable and discussed characters to come out oAlexandria Ocasio
Have you heard the news? Congress is FUN now!Alexandria Ocasio-Cortez, the youngest woman to ever beHow to write a standout resume: 5 tips from 'The Jobfather'
Resumes can be a simple yet highly complex tool to understand. Conflicting advice on how to craft aWhat are the idgaf wars?
On Twitter the idgaf – the acronym for I don't give a fuck – wars rage on. There are cas13 amazing holiday gifts for the person who already has it all
This holiday season, don’t be daunted by the challenge of shopping for that friend or family mThis alignment test will tell you if you're a stupid horny baby
People online love a good alignment test. They also love to say "I'm baby." Here's something that coHere's what to expect from iOS 15
Apple's 2021 Worldwide Developers Conference is just around the corner on June 7, which means the coFoot fetishes explained: everything you need to know
Have you seen Barbieyet? Did you notice the attention lavished upon feet throughout Greta Gerwig's m