Zero-click vulnerability is a vulnerability tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 6, 2025; most recent activity November 6, 2025.
A zero-click vulnerability is a security flaw that can be exploited without any user interaction, enabling attackers to compromise systems or exfiltrate data remotely. These flaws are especially dangerous due to their stealth, broad attack surface, and the difficulty of detection since victims do not need to click or engage with a malicious trigger. In cybersecurity, zero-click flaws raise the bar for attacker capabilities and necessitate stronger, proactive defenses across software platforms, including AI chat services.
Tenable Research identified seven vulnerabilities in OpenAI's ChatGPT models that could allow attackers to steal personal data and manipulate conversations. These flaws, affecting ChatGPT-4o and ChatGPT-5, include…
Tenable Research identified seven critical vulnerabilities in OpenAI's ChatGPT models, including ChatGPT-4o and ChatGPT-5, that could allow attackers to steal personal data and hijack user conversations. The…