Tenable researchers found 7 new vulnerabilities in OpenAI’s ChatGPT, putting users at risk of data theft and safety breaches through new attacks on AI systems dubbed HackedGPT.
Flaws known as HackedGPT were found during testing of OpenAI’s ChatGPT-4o and some persist in ChatGPT-5. OpenAI has fixed some issues, but others remain, risking exploitation. Tenable reports these weaknesses could let attackers secretly access personal data, like saved chats and memory, without users noticing.
A new AI exploit called indirect prompt injection allows attackers to hide malicious instructions within trusted web pages or comments. When ChatGPT engages with this content, it unintentionally follows the embedded commands.
Tenable’s research found that such attacks can occur silently, even without user interaction. In “0-click” attacks, simply asking ChatGPT a question can trigger the exploit, while “1-click” attacks activate malicious commands through a single user click on a link.
Persistent Memory Injection is a troubling method that lets harmful instructions be stored in ChatGPT’s long-term memory. These malicious prompts can persist across sessions, extracting sensitive data until they are manually deleted.
Moshe Bernstein (pictured), Senior Research Engineer at Tenable, said the discovery highlights a fundamental flaw in how large language models determine trust.
“Individually, these flaws seem small — but together they form a complete attack chain, from injection and evasion to data theft and persistence,” Bernstein said. “It shows that AI systems aren’t just potential targets; they can be turned into attack tools that silently harvest information from everyday chats or browsing.”
The seven vulnerabilities identified include:
Indirect prompt injection via trusted sites – Malicious instructions hidden within legitimate online content.
0-click prompt injection – Compromise triggered automatically during browsing or search.
1-click prompt injection – Activation via seemingly safe links.
Safety mechanism bypass – Exploiting trusted wrapper URLs to disguise malicious sites.
Conversation injection – Using ChatGPT’s own browsing system to insert commands into ongoing chats.
Malicious content hiding – Concealing harmful instructions within formatted code or markdown.
Persistent memory injection – Inserting lasting instructions into long-term memory for ongoing data leakage.
Exploited vulnerabilities could let attackers insert hidden commands, steal information from chat histories or linked services, and manipulate responses to spread misinformation.
Tenable’s researchers responsibly shared their findings and cautioned that other AI systems with browsing or memory features might have similar vulnerabilities. They advise AI developers to isolate and sandbox these features, validate safety filters, and enforce zero-trust principles on AI inputs.
For security teams, Tenable advises treating AI models as live attack surfaces. Recommended actions include:
Monitoring AI integrations for signs of manipulation or data leakage.
Testing defences against injection and exfiltration attempts.
Implementing governance and data-classification controls around AI usage.
Bernstein said the findings should serve as a wake-up call for the industry.
“This research isn’t just about exposing flaws — it’s about changing how we secure AI,” he said. “People and organizations alike need to assume that AI tools can be manipulated and design controls accordingly.” That means governance, data safeguards, and continuous testing to make sure these systems work for us, not against us.”
As generative AI becomes part of business and government systems, HackedGPT emphasizes an important fact: AI’s benefits need strong security measures.
InfoSecBulletin Cybersecurity for mankind
