Knowledge Centre
Home / News / Cyber Insurance News / Researchers uncover critical vulnerabilities in ChatGPT that enable prompt-injection attacks

Researchers uncover critical vulnerabilities in ChatGPT that enable prompt-injection attacks

Published on November 17, 2025. EST READ TIME: 2 minutes

Researchers uncover critical vulnerabilities in ChatGPT that enable prompt-injection attacks

Researchers from Tenable and partner academic institutions have uncovered a set of seven critical vulnerabilities in ChatGPT models, including GPT‑4o and GPT‑5, that allow attackers to bypass safety mechanisms via prompt-injection techniques. The flaws include indirect prompt injection through trusted websites, one-click or zero-click attacks that exploit the model’s browsing and summarisation functions, and memory persistence methods that enable the model to exfiltrate personal data without user input. The researchers warn that exposing AI chatbots to external tools and systems increases their attack surface, making them vulnerable to commands hidden in seemingly benign content.

While some of the issues have been addressed by the provider, others remain, suggesting the broader challenge of fully securing large language models.

Source: thehackernews.com

Awards & Recognition
Image

BFSI Leadership Awards 2022 - Product Innovator of the Year (Optima Secure)

ETBFSI Excellence Awards 2021

FICCI Insurance Industry
Awards September 2021

ICAI Awards 2015-16

SKOCH Order-of-Merit

Best Customer Experience
Award of the Year

ICAI Awards 2014-15

Image

CMS Outstanding Affiliate World-Class Service Award 2015

Image

iAAA rating

Image

ISO Certification

Image

Best Insurance Company in Private Sector - General 2014

View all awards