ended6월 2일· 1 sources

ChatGPT for Google Sheets가 워크북을 외부 유출함

Why it matters

ChatGPT for Google Sheets, despite 185,000+ downloads in its first month, is vulnerable to prompt injection attacks through untrusted data sources. Attackers can manipulate the AI into executing unauthorized external scripts without user approval, enabling cascading workbook exfiltration (up to 12 documents) and phishing overlays that impersonate the extension itself. This reveals fundamental security risks when AI models operate with user-level permissions in integrated environments, highlighting the need for structural security review beyond OpenAI's Apps Script code generation removal.

1
Sources
+0
24h
Growth
69d
Active
ChatGPT for Google SheetsPrompt injectionData exfiltrationPhishing overlayApps Script

Sources

Related Issues