logo

ChatGPT's Memory Feature Supercharges Prompt Injection

ID: 5ab26c6b-a961-5d2d-bb77-039def24899d

STIX ID: report--5ab26c6b-a961-5d2d-bb77-039def24899d

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Radware researchers demonstrated "ZombieAgent," a proof-of-concept that amplifies indirect prompt injection (IPI) attacks against ChatGPT by abusing connectors (e.g., email integrations) and the model's long-term memory to persist malicious instructions and exfiltrate data via encoded URL schemes; OpenAI later implemented mitigations restricting attacker-supplied domains and modified-URL usage, but Radware warns structural defenses (like source-trust and intent-awareness) are still needed to fully address such risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.