Seven Ways Hackers Can Make ChatGPT Talk Too Much

Cybersecurity firm Tenable has identified seven vulnerabilities within OpenAI’s ChatGPT that could allow attackers to steal user data, bypass safety systems, and implant persistent threats in the model’s memory.

The research, collectively dubbed HackedGPT, found that several flaws discovered in ChatGPT-4o continued to exist in ChatGPT-5. Tenable said the issues expose users to risks such as data exfiltration, safety override, and long-term compromise through indirect prompt injection — a technique where hidden instructions on external sites can manipulate AI behaviour.

“These flaws expose a fundamental weakness in how large language models judge what information to trust,” said Senior Research Engineer at Tenable, Moshe Bernstein. “Individually, these flaws seem small — but together they form a complete attack chain, from injection and evasion to data theft and persistence.”

Among the vulnerabilities discovered were “0-click” and “1-click” attacks, where simply asking a question or clicking a link could trigger malicious commands. More alarmingly, a method called Persistent Memory Injection could allow hidden instructions to remain stored in ChatGPT’s memory, leading to repeated data leaks even after sessions end.

Tenable warned that the attacks exploit ChatGPT’s browsing and memory functions, which interact with live web data and retain user information. These weaknesses could enable attackers to secretly access chat histories or connected services such as Google Drive.

While OpenAI has addressed some of the vulnerabilities, others remain unpatched in ChatGPT-5, leaving certain exposure paths open, according to Tenable’s findings.

Tenable recommended that AI developers strengthen defences against prompt injection by ensuring browsing, search, and memory systems are isolated to prevent cross-context manipulation.

“This research isn’t just about exposing flaws — it’s about changing how we secure AI,” Bernstein added. “People and organisations alike need to assume that AI tools can be manipulated and design controls accordingly.”

The company urged security teams to treat AI systems as active attack surfaces and to continuously audit their outputs for signs of manipulation or data leakage.

Latest News

Must read