OpenAI Vulnerability Disclosure and Response
By
requilence
Kettled twice. Extra chewy, extra trustworthy.
Summary
A vulnerability allowing access to chat responses intended for other users was reported to OpenAI, potentially exposing personal data and confidential information. The issue remains unpatched despite acknowledgment from OpenAI.
Key quotes
· 3 pulledThe flaw allows peeking at chat responses intended for other users.
OpenAI acknowledged receipt with an automated reply, but I haven't received a human follow-up.
The leaked responses show signs of being real conversations.
You might also wanna read

Security Researchers Discover ChatGPT Vulnerability That Could Extract Sensitive Gmail Data
Security researchers from Radware discovered a vulnerability called 'Shadow Leak' that allowed ChatGPT to be manipulated into extracting sen

OpenAI to let ChatGPT connect to bank accounts via Plaid integration
OpenAI is introducing a new feature that allows ChatGPT users to connect their bank accounts via Plaid, a platform used by over 12,000 finan
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
ChatGPT prompt injection vulnerability allows web pages to serve as phishing payloads
A security researcher discovered a prompt injection vulnerability in ChatGPT where the AI cannot distinguish between its own generated conte
ChatGPT prompt injection vulnerability allows web pages to serve as phishing payloads
A security researcher discovered a prompt injection vulnerability in ChatGPT where the AI cannot distinguish between its own generated conte

Microsoft's NLWeb Protocol Faces Early Security Flaw, Exposing Sensitive Data
Researchers discovered a critical vulnerability in Microsoft's NLWeb protocol, which was recently introduced as a revolutionary tool for int
