# PIR-2026-0015 - SpAIware: persistent memory poisoning of the ChatGPT macOS app for continuous exfiltration

- `id`: PIR-2026-0015
- `title`: Indirect prompt injection plants persistent instructions in ChatGPT's Memory, exfiltrating all future conversations ("SpAIware")
- `date_occurred`: n/a (researcher demonstration; no confirmed in-wild occurrence)
- `date_detected`: 2024-09 (researcher disclosure after coordinated report to OpenAI)
- `date_disclosed`: 2024-09 (Embrace The Red writeup + independent press same week)
- `status`: corroborated (primary researcher writeup with video, vendor patch confirmed, independent coverage)

### The agent
- `agent_description`: ChatGPT macOS desktop app with the Memory feature; browsing/document analysis supplies untrusted input; persistent Memory carries state into every future session.
- `operator_type`: enterprise (OpenAI-operated consumer product)
- `autonomy_level`: human-on-the-loop (user drives the chat, but planted memory acts in every future session without the user's awareness)
- `model_stack`: hosted OpenAI models behind the ChatGPT app (GPT-4o generation at the time); flaw is app/feature level, not model-specific
- `harness`: ChatGPT macOS app < v1.2024.247 (Memory + image-markdown URL rendering)

### Authority
- `authority_scope`: data access (entire future conversation stream), memory write (persistent state), external comms (auto-fetched image-markdown URLs - the exfil channel)
- `funds_at_risk_usd`: 0
- `blast_radius`: customers/third parties (any targeted user of the app; per-victim, not fleet-wide)

### The failure
- `root_cause`: memory-poisoning (primary); contributing prompt-injection (the delivery vector)
- `failure_locus`: harness (app-level: persistent Memory writable from untrusted content + unsafe URL auto-fetch; provider-operated)
- `mechanism`: A malicious website or document analyzed by ChatGPT carries hidden instructions that write attacker commands into persistent Memory. Because Memory loads into every future conversation, all subsequent user messages and replies are appended to an attacker URL rendered as a markdown image and auto-fetched - continuous exfiltration surviving session end and chat deletion. OpenAI patched the exfiltration vector in macOS app v1.2024.247; the memory-injection primitive itself remains a design-level risk.
- `adversary_present`: yes in the demonstrated scenario (attacker-planted content); no known real-world attacker
- `exploitation_status`: researcher-demonstrated (production app, working end-to-end demo; no known in-wild use)

### Impact
- `severity`: near-miss (full demonstrated exposure path; zero known realized loss)
- `direct_loss_usd`: 0
- `indirect_loss_usd`: 0 known
- `downtime`: none
- `data_exposure`: none confirmed in the wild; demo showed full conversation-stream exfiltration

### Detection and recovery
- `detected_by`: third-party (independent researcher Johann Rehberger, coordinated disclosure)
- `time_to_detect`: n/a (vulnerability, not a discrete event)
- `time_to_recover`: exfil vector closed in v1.2024.247
- `remediation`: vendor patch blocking the URL-fetch exfil channel in the macOS app
- `structural_fix`: partial - the exfil channel is closed but attacker-writable persistent memory remains; user-side memory review is the remaining mitigation
- `controls_that_worked`: coordinated disclosure worked as intended; the Memory UI makes planted state user-inspectable (a weak detective control, but the only one that survives the patch)

### Evidence
- `telemetry_grade`: operator-logs (researcher's own demo recordings; vendor patch corroborates the flaw was real)
- `sources`:
  - https://embracethered.com/blog/posts/2024/chatgpt-macos-app-persistent-data-exfiltration/ (primary, researcher)
  - https://thehackernews.com/2024/09/chatgpt-macos-flaw-couldve-enabled-long.html (independent)
  - https://www.scworld.com/brief/prolonged-spyware-injection-possible-with-chatgpt-macos-flaw (independent)
  - `independence`: good - primary researcher plus independent outlets, patch confirmed via vendor version.
- `confidence`: high on mechanism and patch; the open question is whether it was ever exploited in the wild before the fix (no evidence either way)
