ChatGPT for Google Sheets exfiltrates workbooks

A security vulnerability in the 'ChatGPT for Google Sheets' extension allowed for indirect prompt injection, enabling attackers to exfiltrate data and execute phishing attacks. OpenAI has responded by disabling the model's ability to generate Apps Script code to mitigate the risk.
Why it matters
This incident underscores the significant security risks associated with integrating AI agents into productivity software and the potential for automated data exfiltration.
ChatGPT for Google Sheets is vulnerable to data exfiltration and phishing overlay attacks that affect workbooks across the victim’s account after an indirect prompt injection in a single sheet.
The report is a factual summary of a security vulnerability and the subsequent vendor response.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in