Skip to content
ChatGPT for Google Sheets Plugin Exposes Serious Data Exfiltration Risks

ChatGPT for Google Sheets Plugin Exposes Serious Data Exfiltration Risks

First seen 1 Jun 2026, 19:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 2, 2026 at 19:12 UTC

A cybersecurity report from PromptArmor has revealed significant vulnerabilities in the 'ChatGPT for Google Sheets' plugin, which has over 185,000 downloads. The vulnerabilities stem from an indirect prompt injection attack that allows hackers to exfiltrate sensitive data across user accounts without authorization. Malicious scripts can be triggered by importing seemingly benign datasets, leading to the unauthorized access of financial models and other sensitive workbooks. Additionally, the attack can deploy phishing overlays that mimic official authentication pop-ups, tricking users into revealing their credentials. The report indicates that multiple workbooks can be compromised simultaneously, with one incident resulting in the exfiltration of 12 workbooks. OpenAI has been notified of these vulnerabilities but has not responded substantively. Security experts are advising users to review and manage permissions for AI extensions immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 100d ago How this analysis works

Timeline

2026-05-31
PromptArmor reports vulnerabilities in ChatGPT for Google Sheets
The report details how indirect prompt injection can lead to data exfiltration and phishing attacks, affecting over 185,000 users.
News.Ycombinator
2026-06-01
Aibase covers the security warning
Aibase reports on the vulnerabilities highlighted by PromptArmor, emphasizing the risks of data harvesting and phishing overlays.
News.Aibase

More articles in this cluster (2)

Following this threat?

Track OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed