Securitybrief
Seven ChatGPT Vulnerabilities Expose User Data to Theft and Hijacking
First seen 2 Dec 2025, 18:33 UTC
•



+2
•19.4
Export
Article Content
Browse articles
Tenable Research identified seven critical vulnerabilities in OpenAI's ChatGPT models, including ChatGPT-4o and ChatGPT-5, that could allow attackers to steal personal data and hijack user conversations. The vulnerabilities involve indirect prompt injections and other techniques that could lead to data exfiltration and persistent malicious control over the AI's responses. Some issues remain unresolved, posing ongoing risks to users.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical RCE Vulnerabilities Under Active Exploitation
AI Cyberattacks Targeting Critical Infrastructure Escalate
Kimsuky Expands AI Capabilities for Cyberattacks
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
U.S. Accuses Chinese AI Firms of Systematic Distillation of Proprietary Models
Resurgence of KV Botnet Linked to Chinese State Actors