Skip to content
Seven ChatGPT flaws expose user data to attack, Tenable warns

Seven ChatGPT flaws expose user data to attack, Tenable warns

Securitybrief [email protected] (Sean Mitchell) November 6, 2025

Tenable Research has identified seven vulnerabilities in ChatGPT, initially observed in ChatGPT-4o and with several issues persisting in ChatGPT-5, that could allow the theft of personal data and compromise user privacy.

The research, conducted under responsible disclosure protocols, revealed a series of flaws dubbed collectively as "HackedGPT", highlighting multiple routes through which attackers could exfiltrate user data by exploiting ChatGPT's web browsing and memory functions. While OpenAI has resolved some of the vulnerabilities, others remained unaddressed at the time of reporting, leaving certain exploit paths accessible to potential attackers.

Central to Tenable's findings is a security weakness known as indirect prompt injection. In this method, attackers embed hidden instructions within online content - such as on blogs or message boards - which are then unwittingly executed by ChatGPT when it processes those pages. This means that the model can be coerced into taking unauthorised actions simply by retrieving data from the web, thereby bypassing user intent and safety restrictions.

The identified vulnerabilities expose several entry points for attack, including "0-click" scenarios where no user interaction is needed, and "1-click" attacks, requiring only a click on a malicious link. Particularly significant is what researchers call Persistent Memory Injection, where hazardous instructions are saved within ChatGPT's memory and remain active across sessions, creating opportunities for ongoing private data leakage.

Breakdown of vulnerabilities

Tenable's research details seven specific techniques and vulnerabilities:

Risks and implications

Given ChatGPT's widespread adoption for business, academic, and personal communication, the potential consequences of these vulnerabilities include unauthorised insertion of commands into conversations, theft of sensitive information from chat logs or linked accounts, exfiltration through browsing integration, and manipulation of AI-generated responses.

While some vulnerabilities have been addressed, Tenable noted that several remain unpatched in ChatGPT-5. The company has recommended that vendors fortify their systems against such attacks by ensuring safety mechanisms are robust and by isolating browsing, , and memory features to mitigate against cross-context exploitation.

Advice for security professionals

Tenable's recommendations to IT security teams include approaching AI systems as active attack surfaces, conducting regular auditing and monitoring for manipulation or data leaks, investigating anomalies that might indicate prompt injection, and establishing strict governance and data classification for AI use.

Extracted Entities