Researchers at Black Hat revealed a vulnerability in OpenAI's ChatGPT Connectors allowing sensitive data extraction from linked accounts via indirect prompt injection. A single "poisoned" document can compromise a Google Drive account, enabling extraction of API keys and other secrets without user interaction. The attack, dubbed AgentFlayer, exploits a zero-click vulnerability, requiring only the target's email address. OpenAI has reportedly implemented mitigations, but the incident underscores the risks of connecting AI models to external systems and highlights the need for robust prompt injection protections.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments