Article 704MM New attack on ChatGPT research agent pilfers secrets from Gmail inboxes

New attack on ChatGPT research agent pilfers secrets from Gmail inboxes

by
Dan Goodin
from Ars Technica - All content on (#704MM)

The face-palm-worthy prompt injections against AI assistants continue. Today's installment hits OpenAI's Deep Research agent. Researchers recently devised an attack that plucked confidential information out of a user's Gmail inbox and sent it to an attacker-controlled web server, with no interaction required on the part of the victim and no sign of exfiltration.

Deep Research is a ChatGPT-integrated AI agent that OpenAI introduced earlier this year. As its name is meant to convey, Deep Research performs complex, multi-step research on the Internet by tapping into a large array of resources, including a user's email inbox, documents, and other resources. It can also autonomously browse websites and click on links.

A user can prompt the agent to search through the past month's emails, cross-reference them with information found on the web, and use them to compile a detailed report on a given topic. OpenAI says that it accomplishes in tens of minutes what would take a human many hours."

Read full article

Comments

External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments