This ‘ZombieAgent’ zero click vulnerability allows for silent account takeover – here’s what we know

  • OpenAI’s new “apps” feature enables ChatGPT to connect with external services like email and storage
  • Radware discovered “ZombieAgent,” a prompt injection flaw allowing hidden commands to exfiltrate or propagate data
  • Exploits include zero-click, one-click, persistence, and worm-like propagation; OpenAI patched it December 16

OpenAI recently introduced a new feature for ChatGPT which, unfortunately, also puts users at risk of data exfiltration and persistent access.

In December 2025, a feature called Connectors finally moved out of beta and into general availability. This feature allows ChatGPT to connect to numerous other apps, such as calendars, cloud storage, email accounts, and similar – gaining more context and thus providing users with better, more relevant responses.

The feature is now called ‘apps’ but, according to security researchers Radware, also opens up the tool to a major vulnerability – prompt injection attacks.

Four methods of abuse

Radware dubbed the vulnerability ‘ZombieAgent’ and in practice, it’s not that much different from the vulnerabilities we’ve seen in Gemini and other GenAI tools.

Connecting ChatGPT to, Gmail, for example, allows the tool to read incoming emails and give contextual answers about conversations, scheduled calls and meetings, pending invitations, and similar.

However, an incoming email could contain a hidden malicious prompt – something written in white font on a white background, or with font size 0. Invisible to the human eye, but still readable by the machine.

If the victim asks ChatGPT to read that email, the tool could execute those hidden commands without user consent or interaction. The commands could be pretty much anything, from exfiltrating sensitive data to a third-party server, to using the inbox to propagate further.

Radware identified four ways in which ZombieAgent can be abused – a zero-click server-side attack (the malicious prompt is in the email and ChatGPT exfiltrates data before the user even sees the content), one-click server-side attack (the prompt is in a file which the user must first upload), gaining persistence (a malicious command designed to be stored into ChatGPT’s memory), and propagation (the malicious prompt is used to propagate further, like a worm).

Radware said OpenAI fixed the problem on December 16 but did not detail how.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Bungie’s Marathon shooter launches on March 5th

Bungie is putting an official date on Marathon today, its delayed extraction shooter. The slick-looking shooter from the makers of Halo and Destiny was...

A second US Sphere could come to Maryland

Sphere Entertainment, the company behind the eye-catching interactive venue in Las Vegas, has announced its "intent to develop" another Sphere in Maryland that will...

Musk claims Tesla will restart work on its Dojo supercomputer

Elon Musk posted on X that Tesla will be restarting work on Dojo3, the third generation of its in-house supercomputer project. The Dojo team...

Bungie’s Marathon arrives on March 5

Marathon, Bungie's long-awaited extraction shooter, will arrive on March 5, the studio announced today. Alongside a definitive release date, Bungie shared a new gameplay...

More malicious browser extensions uncovered – Chrome, Firefox, and Edge all affected

LayerX found 17 malicious browser extensions with 840,000+ downloads Extensions hijacked affiliate links, injected tracking, and enabled ad fraudAll extensions removed, but users must...

The world’s first Gemini-powered EV lands this week, but the Volvo EX60 needs to be better than Alexa+ on the BMW iX3

The Volvo EX60 will be the first to ship with Google Gemini built-inVolvo is promising "natural conversation" between man and machineLatest hardware from Nvidia...

MIO: Memories in Orbit is a pleasant stroll after the brutal ultramarathon of Hollow Knight: Silksong — and I’m here for it

When I booted up last year’s tough-as-nails and long-awaited Hollow Knight: Silksong, I knew I had to focus up and lock in – this...

Tour Down Under 2026 Free Streams: TV Channels, Schedule & Preview of UCI WorldTour Opener

Stream Tour Down Under 2026 completely *FREE* on 7Plus (AUS)Use NordVPN to watch from anywherePrologue: January 20 — Adelaide → Adelaide (3.6km)Start Time: 6pm...

How to watch The Secret of Me on Channel 4 — it’s *FREE*

Watch The Secret of Me for free on Channel 4 (UK restricted)Watch The Secret of Me for free on ABC iView (AUS restricted)Abroad? Watch...

ChatGPT now has ads, and before long Gemini might too – here’s what we can learn from Netflix, Prime Video, and other streaming services

The time has come, OpenAI has finally announced the thing we all knew was coming but didn't want to believe: ChatGPT is getting ads.The...