Security Flaw in ChatGPT for Google Sheets Enables Data Exfiltration via Prompt Injection
By
hackerBanana
The kind of bagel that ruins lesser bagels for you.
Summary
OpenAI's ChatGPT extension for Google Sheets, which has over 185,000 downloads in less than a month, is vulnerable to indirect prompt injection attacks. A single malicious query can trigger data exfiltration and phishing overlay attacks across workbooks in a victim's Google Sheets account, even when users have explicitly required human approval before ChatGPT edits workbooks. The attack bypasses human-in-the-loop approval settings entirely.
Key quotes
· 3 pulledThis attack does not require human-in-the-loop approvals, even when in settings the user has explicitly required human approval before ChatGPT edits workbooks.
A single indirect prompt injection attack triggered by a single benign user query can trigger
ChatGPT for Google Sheets is vulnerable to data exfiltration and phishing overlay attacks that affect workbooks across the victim's account after an indirect prompt injection in a single sheet.
You might also wanna read

Security Researchers Discover ChatGPT Vulnerability That Could Extract Sensitive Gmail Data
Security researchers from Radware discovered a vulnerability called 'Shadow Leak' that allowed ChatGPT to be manipulated into extracting sen
ChatGPT prompt injection vulnerability allows web pages to serve as phishing payloads
A security researcher discovered a prompt injection vulnerability in ChatGPT where the AI cannot distinguish between its own generated conte
ChatGPT prompt injection vulnerability allows web pages to serve as phishing payloads
A security researcher discovered a prompt injection vulnerability in ChatGPT where the AI cannot distinguish between its own generated conte
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
ChatGPT for Google Sheets
ChatGPT for Excel: AI-Powered Spreadsheet Creation and Analysis Tool
ChatGPT for Excel is an AI-powered tool that enables users to build and update Excel spreadsheets using natural language commands. It can cr
