news.mlab.sh
Back to the feed
threat-intel

Researcher Claims Control of ChatGPT Secure Sandbox

High
Image: Dark Reading
Summary

A Palo Alto Networks researcher, Simcha Kosman, demonstrated a proof-of-concept attack that allowed him to establish command and control within ChatGPT’s secure sandbox. The attack leveraged differences in URL handling across iOS and macOS to inject malicious code, steal data, and ultimately achieve full C2 communication entirely within the sandbox. OpenAI has addressed several of Kosman’s findings, including removing the vulnerability related to URL handling and addressing a denial-of-service issue through Artifactory. This highlights a significant security concern regarding the isolation of ChatGPT’s sandboxes.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.