id: PIR-2026-0015title: Indirect prompt injection plants persistent instructions in ChatGPT's Memory, exfiltrating all future conversations ("SpAIware")date_occurred: n/a (researcher demonstration; no confirmed in-wild occurrence)date_detected: 2024-09 (researcher disclosure after coordinated report to OpenAI)date_disclosed: 2024-09 (Embrace The Red writeup + independent press same week)status: corroborated (primary researcher writeup with video, vendor patch confirmed, independent coverage)agent_description: ChatGPT macOS desktop app with the Memory feature; browsing/document analysis supplies untrusted input; persistent Memory carries state into every future session.operator_type: enterprise (OpenAI-operated consumer product)autonomy_level: human-on-the-loop (user drives the chat, but planted memory acts in every future session without the user's awareness)model_stack: hosted OpenAI models behind the ChatGPT app (GPT-4o generation at the time); flaw is app/feature level, not model-specificharness: ChatGPT macOS app < v1.2024.247 (Memory + image-markdown URL rendering)authority_scope: data access (entire future conversation stream), memory write (persistent state), external comms (auto-fetched image-markdown URLs - the exfil channel)funds_at_risk_usd: 0blast_radius: customers/third parties (any targeted user of the app; per-victim, not fleet-wide)root_cause: memory-poisoning (primary); contributing prompt-injection (the delivery vector)failure_locus: harness (app-level: persistent Memory writable from untrusted content + unsafe URL auto-fetch; provider-operated)mechanism: A malicious website or document analyzed by ChatGPT carries hidden instructions that write attacker commands into persistent Memory. Because Memory loads into every future conversation, all subsequent user messages and replies are appended to an attacker URL rendered as a markdown image and auto-fetched - continuous exfiltration surviving session end and chat deletion. OpenAI patched the exfiltration vector in macOS app v1.2024.247; the memory-injection primitive itself remains a design-level risk.adversary_present: yes in the demonstrated scenario (attacker-planted content); no known real-world attackerexploitation_status: researcher-demonstrated (production app, working end-to-end demo; no known in-wild use)severity: near-miss (full demonstrated exposure path; zero known realized loss)direct_loss_usd: 0indirect_loss_usd: 0 knowndowntime: nonedata_exposure: none confirmed in the wild; demo showed full conversation-stream exfiltrationdetected_by: third-party (independent researcher Johann Rehberger, coordinated disclosure)time_to_detect: n/a (vulnerability, not a discrete event)time_to_recover: exfil vector closed in v1.2024.247remediation: vendor patch blocking the URL-fetch exfil channel in the macOS appstructural_fix: partial - the exfil channel is closed but attacker-writable persistent memory remains; user-side memory review is the remaining mitigationcontrols_that_worked: coordinated disclosure worked as intended; the Memory UI makes planted state user-inspectable (a weak detective control, but the only one that survives the patch)telemetry_grade: operator-logs (researcher's own demo recordings; vendor patch corroborates the flaw was real)sources:independence: good - primary researcher plus independent outlets, patch confirmed via vendor version.confidence: high on mechanism and patch; the open question is whether it was ever exploited in the wild before the fix (no evidence either way)