logo

AgentFlayer 0-click exploit abuses ChatGPT Connectors to Steal 3rd-party app data

ID: 3b325cfe-e5af-5599-b359-5fbd112a669e

STIX ID: report--3b325cfe-e5af-5599-b359-5fbd112a669e

Feed Name: HackRead

Threat Score
75/100

Date Published: 2025-08-10

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

AgentFlayer is a demonstrated zero-click vulnerability in ChatGPT Connectors that uses indirect prompt injection—hidden instructions embedded in uploaded documents—to coerce the model into searching connected services (Google Drive, SharePoint) and exfiltrating secrets (such as API keys) via crafted image links. Presented by Zenity at Black Hat, the proof-of-concept shows existing guardrails can be bypassed and underscores a broader class of risks arising from linking LLM agents to third-party applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.