/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How a security researcher used a now-fixed flaw to store false memories in ChatGPT via indirect prompt injection to exfiltrate all user input in perpetuity

Emails, documents, and other untrusted content can plant malicious memories.  —  When security researcher Johann Rehberger recently reported …

Ars Technica Dan Goodin

Context & Ripple Effects

The finding turns ChatGPT memory into a security boundary: untrusted material such as email or documents could affect not just one response but later interactions. That makes it distinct from one-off jailbreaks, because the compromised state could persist after the original content was gone.

It also fits a repeat pattern in the related coverage. Rehberger later demonstrated a Gemini defense bypass that could plant long-term memories, while a separate OpenAI Connector weakness showed how indirect injection could extract data from a connected Google Drive account.

First-order effects

  • During the vulnerable period, users who let ChatGPT process attacker-controlled content risked having false memory instructions stored and future input exfiltrated; the reported fix closes that specific path.
  • OpenAI must treat memory creation and modification as sensitive actions, rather than as ordinary model output shaped by whatever content a user supplies.

Second-order effects

  • AI providers adding document, email, and connector access face pressure to isolate untrusted content from durable user state and to make memory writes more auditable and reversible.
  • Enterprise users may need tighter controls over which external sources can feed assistants, since a single poisoned artifact can turn a convenience feature into a continuing data-exposure channel.

Third-order effects

  • If persistent memory and tool access continue to converge, prompt injection becomes an identity-and-state integrity problem, not merely a model-behavior problem; safeguards will need to govern what an assistant is allowed to remember and act on.
  • The durable design divide may be between assistants that preserve a strict trusted-tool boundary and those that let retrieved content influence long-lived preferences or permissions without clear provenance.

The trend: This is one data point in the expansion of the agentic attack surface as AI systems retain context and ingest more untrusted external data.

Discussion

  • @reedmideke@mastodon.social Reed Mideke on mastodon
    Infosec people: Untrusted, unsanitized inputs have been the bane of our existence for the last 40 years  —  Tech CEOs: We're betting billions of dollars the next big thing is a black box filled with pure essence of untrusted, unsanitizable inputs  —  https://arstechnica.com/...  …
  • @gregpiper Greg Piper on x
    OpenAI blew him off when he reported the vulnerability. https://arstechnica.com/... [image]
  • @grandiopanda @grandiopanda on x
    🚨 Wake up, folks! A hacker just showed us how easy it is to plant false memories in ChatGPT and siphon YOUR data eternally. This isn't just a “safety issue” - it's the Wild West of info theft! 😱💻 Don't trust everything that remembers! #DataPrivacy #H https://arstechnica.com/...
  • @hayata_yamamoto @hayata_yamamoto on x
    むむ。そ ういうのも ; あるのか > “The prompt injection inserted a memory into ChatGPT's long-term storage. When you start a new conversation, it actually is still exfiltrating the data.” https://arstechnica.com/...
  • @wunderwuzzi23 Johann Rehberger on x
    🤔 What do you get when you combine Prompt Injection + Data Exfiltration + Long-term Memory? 👉 Persistent SpAIware! 🚨 OpenAI fixed a persistent data exfiltration issue in the macOS ChatGPT app that I reported. 🔒 Make sure to stay up to date and use the latest ChatGPT app [video]