← Back to feed
AI SecurityEmerging1 sourceAug 1, 2025 · 15:00via Embrace The Red (AI agent security)

Exfiltrating Your ChatGPT Chat History and Memories With Prompt Injection

Brief

In this post we demonstrate how a bypass in OpenAI’s “safe URL” rendering feature allows ChatGPT to send personal information to a third-party server. This can be exploited by an adversary via a prompt injection via untrusted data.

If you process untrusted content, like summarizing a website, or analyze a pdf document, the author of that document can exfiltrate any information present in the prompt context, including your past chat history.

Read more on Embrace The Red (AI agent security)