Israeli research reveals ChatGPT weak spots, saves millions from hacking
Damn those juices for white-hatting humanity yet again. | [Ynet] The research group of the Israeli-American cyber company Imperva revealed on Monday a series of security vulnerabilities in the popular AI chatbot ChatGPT. According to the researchers, these vulnerabilities could have allowed hackers to take over user accounts without the need for login information. This is a severe problem that could have revealed a lot of personal information due to the diverse tasks undertaken by the chatbot and the fact that it saves conversation histories.
ChatGPT currently has about 180 million registered users, so the breach could have affected millions of users worldwide and allowed hackers to gain full access to every account on the platform. The vulnerabilities could have been exploited through ChatGPT's file upload mechanism and its citation function from those files.
Additionally, another XSS vulnerability was found that originated in the way ChatGPT cites websites; that is, its ability to read websites. This allowed the company's researchers to run malicious code on the AI platform by embedding it in a malicious website.
Posted by: Grom the Reflective 2024-02-20 |