Tag: cross-site request forgery (CSRF)

New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands
News

New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands

Researchers studying cybersecurity have found a new flaw in OpenAI's ChatGPT Atlas web browser that might let bad actors insert malicious instructions into the memory of the AI-powered assistant and cause it to execute arbitrary code. According to a study published with The Hacker News, LayerX Security Co-Founder and CEO Or Eshed stated that this exploit can enable attackers to implant malware, grant themselves access privileges, or infect systems with malicious code. Fundamentally, the attack takes use of a cross-site request forgery (CSRF) vulnerability that might be used to introduce malicious code into ChatGPT's persistent memory. When a logged-in user tries to utilize ChatGPT for legal purposes, the damaged memory can then remain across devices and sessions, allowing an attacke...