logo

Hacking ChatGPT by Planting False Memories into Its Data

ID: cd26e6f3-c384-5ceb-911c-269181a6f1ef

STIX ID: report--cd26e6f3-c384-5ceb-911c-269181a6f1ef

Feed Name: Schneier on Security

Threat Score
65/100

Date Published: 2024-10-01

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

A researcher found that ChatGPT's long-term memory feature can be manipulated to plant false memories; a subsequent disclosure included a proof-of-concept that caused the ChatGPT macOS app to send all user input and model output to an attacker-controlled server after the model was instructed to view a malicious image, creating a persistent exfiltration channel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.