"Critical ChatGPT Plug-in Vulnerabilities Expose Sensitive Data"
"Critical ChatGPT Plug-in Vulnerabilities Expose Sensitive Data"
Salt Labs researchers discovered three security vulnerabilities in ChatGPT extension functions that could enable unauthorized, zero-click access to users' accounts and services. ChatGPT plug-ins and custom versions of the Artificial Intelligence (AI) system published by developers expand the AI model's capabilities. They enable interactions with external services by granting OpenAI's popular generative AI chatbot access and permission to perform tasks on different third-party websites, including GitHub and Google Drive.