
{"id":121874,"date":"2025-11-09T17:33:21","date_gmt":"2025-11-09T09:33:21","guid":{"rendered":"https:\/\/vertu.com\/?p=121874"},"modified":"2025-11-07T17:52:45","modified_gmt":"2025-11-07T09:52:45","slug":"major-security-alert-seven-critical-vulnerabilities-discovered-in-gpt%e2%80%914o-and-gpt%e2%80%915","status":"publish","type":"post","link":"https:\/\/legacy.vertu.com\/ar\/%d9%86%d9%85%d8%b7-%d8%a7%d9%84%d8%ad%d9%8a%d8%a7%d8%a9\/major-security-alert-seven-critical-vulnerabilities-discovered-in-gpt%e2%80%914o-and-gpt%e2%80%915\/","title":{"rendered":"Major Security Alert: Seven Critical Vulnerabilities Discovered in GPT\u20114o and GPT\u20115"},"content":{"rendered":"<h2 data-start=\"0\" data-end=\"131\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-121885\" src=\"https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5.png\" alt=\"\" width=\"806\" height=\"437\" srcset=\"https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5.png 806w, https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5-300x163.png 300w, https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5-768x416.png 768w, https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5-18x10.png 18w, https:\/\/vertu-website-oss.vertu.com\/2025\/11\/GPT-4o-vs-GPT-5-600x325.png 600w\" sizes=\"(max-width: 806px) 100vw, 806px\" \/><\/h2>\n<p data-start=\"132\" data-end=\"706\">In a startling development, researchers at Tenable have revealed <strong data-start=\"197\" data-end=\"245\">seven previously undisclosed vulnerabilities<\/strong> affecting the latest large language models from OpenAI\u2014GPT-4o and GPT-5. These flaws, uncovered and publicly reported by Cyber Security News, allow <strong data-start=\"394\" data-end=\"416\">zero-click attacks<\/strong> that may enable malicious actors to exfiltrate user data, manipulate memory, and bypass built-in safety mechanisms.\u00a0<br data-start=\"570\" data-end=\"573\" \/>This article examines how these vulnerabilities affect individual users, enterprises, and the trajectory of frontier AI technologies.<\/p>\n<hr data-start=\"708\" data-end=\"711\" \/>\n<h3 data-start=\"713\" data-end=\"766\">What Was Found: The Vulnerabilities at a Glance<\/h3>\n<p data-start=\"767\" data-end=\"793\">According to the report:<\/p>\n<ul data-start=\"794\" data-end=\"1747\">\n<li data-start=\"794\" data-end=\"1046\">\n<p data-start=\"796\" data-end=\"1046\">The vulnerabilities allow indirect prompt injection attacks: malicious instructions embedded in external content (web pages, memory prompts, browsing tools) get processed by the models without user interaction.<\/p>\n<\/li>\n<li data-start=\"1047\" data-end=\"1197\">\n<p data-start=\"1049\" data-end=\"1197\">Attackers can potentially access private user \u201cmemories\u201d and chat history stored by the model\u2019s memory tool.<\/p>\n<\/li>\n<li data-start=\"1198\" data-end=\"1386\">\n<p data-start=\"1200\" data-end=\"1386\">The exploits work with \u201czero-click\u201d workflows: users can simply run innocuous queries (e.g., \u201cgive me dinner ideas\u201d) and still trigger data leaks.<\/p>\n<\/li>\n<li data-start=\"1387\" data-end=\"1581\">\n<p data-start=\"1389\" data-end=\"1581\">These weaknesses stem from the architecture of memory tools, web-browsing modules, and system prompts that bind together user context and external data.<\/p>\n<\/li>\n<li data-start=\"1582\" data-end=\"1747\">\n<p data-start=\"1584\" data-end=\"1747\">Some of the vulnerabilities have already been patch-notified under advisories like TRA-2025-22, TRA-2025-11, TRA-2025-06.<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"1749\" data-end=\"1752\" \/>\n<h3 data-start=\"1754\" data-end=\"1775\">Impact on Users<\/h3>\n<h4 data-start=\"1776\" data-end=\"1811\">Privacy & Data Leakage Risks<\/h4>\n<p data-start=\"1812\" data-end=\"1859\">For everyday users of ChatGPT-style services:<\/p>\n<ul data-start=\"1860\" data-end=\"2366\">\n<li data-start=\"1860\" data-end=\"2067\">\n<p data-start=\"1862\" data-end=\"2067\">If you store personal information (e.g., names, addresses, business details) in the model\u2019s memory tool, these vulnerabilities mean that attackers might extract that data without your active involvement.<\/p>\n<\/li>\n<li data-start=\"2068\" data-end=\"2199\">\n<p data-start=\"2070\" data-end=\"2199\">The \u201czero-click\u201d aspect lowers the barrier: you might be unaware your data is at risk, which undermines trust in AI assistants.<\/p>\n<\/li>\n<li data-start=\"2200\" data-end=\"2366\">\n<p data-start=\"2202\" data-end=\"2366\">For enterprises or professionals using AI tools for sensitive workflows, the risk is amplified: client data, trade secrets, and internal documents might be exposed.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"2368\" data-end=\"2402\">Behavioural Impacts & Trust<\/h4>\n<ul data-start=\"2403\" data-end=\"2838\">\n<li data-start=\"2403\" data-end=\"2547\">\n<p data-start=\"2405\" data-end=\"2547\">Users may become more cautious about what they ask AI models, what information they feed them, or whether they use \u201cmemory\u201d features at all.<\/p>\n<\/li>\n<li data-start=\"2548\" data-end=\"2702\">\n<p data-start=\"2550\" data-end=\"2702\">Some users or organisations may elect to refrain from using the newest models (e.g., GPT-5) until their safety profile is fully validated and audited.<\/p>\n<\/li>\n<li data-start=\"2703\" data-end=\"2838\">\n<p data-start=\"2705\" data-end=\"2838\">There is potential for reputational damage if a model used by a business gets compromised or used as a conduit for data exfiltration.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"2840\" data-end=\"2875\">Mitigation Actions for Users<\/h4>\n<ul data-start=\"2876\" data-end=\"3431\">\n<li data-start=\"2876\" data-end=\"3021\">\n<p data-start=\"2878\" data-end=\"3021\">Be judicious about enabling memory features, or storing highly sensitive information in AI assistants until you trust their security posture.<\/p>\n<\/li>\n<li data-start=\"3022\" data-end=\"3188\">\n<p data-start=\"3024\" data-end=\"3188\">Limit tool-use: if your workflow uses models with web-browsing, file-upload, or memory features, assume they carry heightened risk and apply additional oversight.<\/p>\n<\/li>\n<li data-start=\"3189\" data-end=\"3287\">\n<p data-start=\"3191\" data-end=\"3287\">Monitor for updates from your AI provider (OpenAI in this case) about patches and disclosures.<\/p>\n<\/li>\n<li data-start=\"3288\" data-end=\"3431\">\n<p data-start=\"3290\" data-end=\"3431\">For API integrators: apply user-level logging, restrict memory access, sandbox external data, and consider additional filtering or oversight.<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"3433\" data-end=\"3436\" \/>\n<h3 data-start=\"3438\" data-end=\"3499\">Implications for the AI & Frontier Technology Landscape<\/h3>\n<h4 data-start=\"3500\" data-end=\"3543\">Model Safety & Deployment Strategies<\/h4>\n<ul data-start=\"3544\" data-end=\"4025\">\n<li data-start=\"3544\" data-end=\"3731\">\n<p data-start=\"3546\" data-end=\"3731\">These disclosures signal that <strong data-start=\"3576\" data-end=\"3612\">capability alone is insufficient<\/strong>: deploying large language models with advanced features (memory, browsing, tool use) introduces new attack surfaces.<\/p>\n<\/li>\n<li data-start=\"3732\" data-end=\"3852\">\n<p data-start=\"3734\" data-end=\"3852\">Vendors must treat <strong data-start=\"3753\" data-end=\"3788\">safety, security and robustness<\/strong> as first-class requirements\u2014not just \u201cfeatures to add later.\u201d<\/p>\n<\/li>\n<li data-start=\"3853\" data-end=\"4025\">\n<p data-start=\"3855\" data-end=\"4025\">Enterprises integrating LLMs into mission-critical workflows will likely demand <strong data-start=\"3935\" data-end=\"3957\">third-party audits<\/strong>, <strong data-start=\"3959\" data-end=\"3980\">penetration tests<\/strong>, and <strong data-start=\"3986\" data-end=\"4008\">formal red-teaming<\/strong> before adoption.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"4027\" data-end=\"4065\">Competitive & Ecosystem Effects<\/h4>\n<ul data-start=\"4066\" data-end=\"4561\">\n<li data-start=\"4066\" data-end=\"4182\">\n<p data-start=\"4068\" data-end=\"4182\">Vendors that emphasise safer deployment and transparent vulnerability management may gain competitive advantage.<\/p>\n<\/li>\n<li data-start=\"4183\" data-end=\"4369\">\n<p data-start=\"4185\" data-end=\"4369\">Startups and open-source players will face additional scrutiny: if mainstream closed models show this type of vulnerability, the bar for safe usage of open models rises dramatically.<\/p>\n<\/li>\n<li data-start=\"4370\" data-end=\"4561\">\n<p data-start=\"4372\" data-end=\"4561\">Regulators may increasingly mandate <strong data-start=\"4408\" data-end=\"4432\">security disclosures<\/strong>, <strong data-start=\"4434\" data-end=\"4461\">vulnerability reporting<\/strong>, and <strong data-start=\"4467\" data-end=\"4502\">responsible-deployment criteria<\/strong> for AI models with memory or capability to browse the web.<\/p>\n<\/li>\n<\/ul>\n<h4 data-start=\"4563\" data-end=\"4599\">Innovation vs. Risk Trade-off<\/h4>\n<ul data-start=\"4600\" data-end=\"5126\">\n<li data-start=\"4600\" data-end=\"4812\">\n<p data-start=\"4602\" data-end=\"4812\">Features like memory, tool integration and browsing are powerful enablers of advanced applications (professional assistants, business automation, multimodal workflows). But they also <strong data-start=\"4785\" data-end=\"4809\">magnify risk vectors<\/strong>.<\/p>\n<\/li>\n<li data-start=\"4813\" data-end=\"4971\">\n<p data-start=\"4815\" data-end=\"4971\">The industry may see a bifurcation: \u201csafer mode\u201d LLMs with restricted functionality vs \u201cfeature-rich\u201d models used only in tightly controlled environments.<\/p>\n<\/li>\n<li data-start=\"4972\" data-end=\"5126\">\n<p data-start=\"4974\" data-end=\"5126\">Workflows in enterprises may shift to hybrid models: humans-in-the-loop, regular auditing of AI output, strict access controls on memory\/data retention.<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"5128\" data-end=\"5131\" \/>\n<h3 data-start=\"5133\" data-end=\"5166\">What to Watch Going Forward<\/h3>\n<ul data-start=\"5167\" data-end=\"6013\">\n<li data-start=\"5167\" data-end=\"5316\">\n<p data-start=\"5169\" data-end=\"5316\"><strong data-start=\"5169\" data-end=\"5198\">Patch efficacy & response<\/strong>: Will OpenAI (and other AI vendors) push updates, and how quickly will they close these classes of vulnerabilities?<\/p>\n<\/li>\n<li data-start=\"5317\" data-end=\"5452\">\n<p data-start=\"5319\" data-end=\"5452\"><strong data-start=\"5319\" data-end=\"5341\">Independent audits<\/strong>: How many external security researchers will test these models, publish findings, and push for transparency?<\/p>\n<\/li>\n<li data-start=\"5453\" data-end=\"5658\">\n<p data-start=\"5455\" data-end=\"5658\"><strong data-start=\"5455\" data-end=\"5476\">Regulatory action<\/strong>: Governments may contractually require vendors to report AI vulnerabilities and provide mitigation roadmaps\u2014especially for models used by public sector or critical infrastructure.<\/p>\n<\/li>\n<li data-start=\"5659\" data-end=\"5823\">\n<p data-start=\"5661\" data-end=\"5823\"><strong data-start=\"5661\" data-end=\"5689\">Model versioning choices<\/strong>: Organisations may delay adoption of bleeding-edge models (e.g., GPT-5) and stick with more mature versions until safety is proven.<\/p>\n<\/li>\n<li data-start=\"5824\" data-end=\"6013\">\n<p data-start=\"5826\" data-end=\"6013\"><strong data-start=\"5826\" data-end=\"5861\">User awareness & best practices<\/strong>: As this becomes more widely known, users may demand clear disclosures about AI model capabilities, feature risk, and how their data\/memory is handled.<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"6015\" data-end=\"6018\" \/>\n<h3 data-start=\"6020\" data-end=\"6036\">\u062e\u0627\u062a\u0645\u0629<\/h3>\n<p data-start=\"6037\" data-end=\"6802\">The discovery of seven major vulnerabilities in GPT-4o and GPT-5 highlights a pivotal moment in the evolution of generative AI. For individual users, it underscores the importance of caution when storing sensitive data with AI assistants. For industry, it serves as a wake-up call: model power must be matched by robust security, transparent testing, and responsible deployment.<br data-start=\"6415\" data-end=\"6418\" \/>As generative AI continues to advance into more modalities and tasks, the trade-off between innovation and safety will grow sharper. Models that remember, browse, and act as agents offer tremendous upside\u2014but they also offer attackers new pathways. The future of frontier AI will depend not just on how smart the models become, but how <strong data-start=\"6754\" data-end=\"6792\">secure, trustworthy, and resilient<\/strong> they are.<\/p>","protected":false},"excerpt":{"rendered":"<p>In a startling development, researchers at Tenable have revealed seven previously undisclosed vulnerabilities affecting the latest large language models from [&hellip;]<\/p>","protected":false},"author":11214,"featured_media":121885,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[468],"tags":[],"class_list":["post-121874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-best-post"],"acf":[],"_links":{"self":[{"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/posts\/121874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/users\/11214"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/comments?post=121874"}],"version-history":[{"count":0,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/posts\/121874\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/media\/121885"}],"wp:attachment":[{"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/media?parent=121874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/categories?post=121874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.vertu.com\/ar\/wp-json\/wp\/v2\/tags?post=121874"}],"curies":[{"name":"\u0648\u0648\u0631\u062f\u0628\u0631\u064a\u0633","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}