← the record
AIAAIC-0985

ChatGPT bug exposes user chat histories, payment info

The chat histories and payment details of ChatGPT users were exposed to other users, prompt ing users to complain about poor system robustness, security and privacy. A bug in OpenAI's ChatGPT allowed multiple users to view the titles of other users' conversation histories. The issue first surfaced when a user noticed unfamiliar titles in their chat history sidebar, leading to fears that their account had been hacked. S ome billing details were exposed for a small percentage of users . OpenAI confirmed the glitch, which was attributed to a vulnerability in the redis-py open-source library used for managing user data. According to the company, 'In the hours before we took ChatGPT offline on Monday, it was possible for some users to see another active user’s first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date. Full credit card numbers were not exposed at any time.' Users' conversations with ChatGPT are stored in their chat history bar and can be revisited. System 🤖 ChatGPT Documents 📃 OpenAI (2023). ChatGPT Web Incident Report OpenAI (2023). ChatGPT outage: Here's what happened Operator: OpenAI Developer: OpenAI Country: USA; Global Sector: Multiple Purpose: Provide information, communicate Technology: Chatbot; Generative AI; Machine learning Issue: Privacy; Security

Date it happened
2023-03-01
Organisation involved
OpenAI
Product, system or model
ChatGPT
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.