"Security Risks in ChatGPT Plugins Expose Data and Accounts"

1 min read
Source: The Hacker News
"Security Risks in ChatGPT Plugins Expose Data and Accounts"
Photo: The Hacker News
TL;DR Summary

Third-party plugins for OpenAI ChatGPT could be exploited by threat actors to hijack accounts on third-party websites, such as GitHub, and access sensitive data. Security flaws in ChatGPT and its ecosystem, including OAuth manipulation and zero-click account takeover vulnerabilities, have been uncovered by Salt Labs. Additionally, a new side-channel attack has been identified, allowing attackers to extract encrypted responses from AI assistants by inferring token lengths in network traffic. Countermeasures such as random padding and transmitting tokens in larger groups are recommended to mitigate the effectiveness of the side-channel attack.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

3 min

vs 4 min read

Condensed

88%

72990 words

Want the full story? Read the original article

Read on The Hacker News