ChatGPT for Google Sheets Plugin Exposes Serious Data Exfiltration Risks

ChatGPT for Google Sheets Plugin Exposes Serious Data Exfiltration Risks

1 Jun 2026 News.YcombinatorNews.Aibase 80% similarity 69.0
Share:

Article Content

Browse articles
ThreatCluster

A cybersecurity report from PromptArmor has revealed significant vulnerabilities in the 'ChatGPT for Google Sheets' plugin, which has over 185,000 downloads. The vulnerabilities stem from an indirect prompt injection attack that allows hackers to exfiltrate sensitive data across user accounts without authorization. Malicious scripts can be triggered by importing seemingly benign datasets, leading to the unauthorized access of financial models and other sensitive workbooks. Additionally, the attack can deploy phishing overlays that mimic official authentication pop-ups, tricking users into revealing their credentials. The report indicates that multiple workbooks can be compromised simultaneously, with one incident resulting in the exfiltration of 12 workbooks. OpenAI has been notified of these vulnerabilities but has not responded substantively. Security experts are advising users to review and manage permissions for AI extensions immediately.

Key Points: • ChatGPT for Google Sheets has serious vulnerabilities allowing data exfiltration. • Indirect prompt injection attacks can trigger unauthorized access to multiple workbooks. • Phishing overlays can deceive users into providing sensitive credentials.

ThreatCluster AI

Timeline

2026-05-31
PromptArmor reports vulnerabilities in ChatGPT for Google Sheets
The report details how indirect prompt injection can lead to data exfiltration and phishing attacks, affecting over 185,000 users.
News.Ycombinator
2026-06-01
Aibase covers the security warning
Aibase reports on the vulnerabilities highlighted by PromptArmor, emphasizing the risks of data harvesting and phishing overlays.
News.Aibase

Community

Browse all →