April 3, 2023, 3:45 p.m. | Roman Samoilenko

System Weakness - Medium systemweakness.com

New prompt injection attack on ChatGPT web version. Markdown images can steal your chat data.

Source: https://www.linkedin.com/pulse/newly-discovered-prompt-injection-tactic-threatens-large-anderson

It uses single-pixel image that steals your sensitive chat data and sends it to a malicious third-party.
Full PDF-version — https://kajojify.github.io/articles/1_chatgpt_attack.pdf

Attack description

I’ve discovered new prompt injection attack aimed at the users of ChatGPT web version. The attack lets perform a prompt injection on ChatGPT chat, modifying chatbot answer with an invisible single-pixel markdown image that exfiltrates the user’s sensitive chat data …

ai attack chatgpt injection privacy prompt-engineering prompt injection security version web

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC