Skip to content

New 'Man-in-the-Prompt' Attack Targets AI Chatbots Like ChatGPT

Browser extensions are putting your AI interactions at risk. Learn about the new 'Man-in-the-Prompt' attack and how to protect yourself.

In the picture we can see three boys standing near the desk on it, we can see two computer systems...
In the picture we can see three boys standing near the desk on it, we can see two computer systems towards them and one boy is talking into the microphone and they are in ID cards with red tags to it and behind them we can see a wall with an advertisement board and written on it as Russia imagine 2013.

New 'Man-in-the-Prompt' Attack Targets AI Chatbots Like ChatGPT

A new cyber threat, dubbed 'Man-in-the-Prompt', has emerged, targeting AI chatbots like ChatGPT and Gemini. This attack exploits browser extensions to access and manipulate user prompts without their knowledge or consent.

The threat is particularly concerning as 99% of business users have at least one browser extension installed, increasing risk exposure. The attack, similar to prompt injection, involves intercepting, modifying, or rewriting user prompts to steal data or manipulate responses. AI security must now consider the user interface and browser environment, as simple HTML text fields can become system vulnerabilities.

Researchers have proven this technique works on major AI tools, including ChatGPT, Gemini, Copilot, Claude, and DeepSeek. To mitigate this risk, individual users should regularly check installed extensions and limit their permissions. Businesses should consider blocking or monitoring extensions on company devices. To distinguish reliable content from potential manipulations, prompt signing and 'spotlighting' techniques can be employed.

The 'Man-in-the-Prompt' attack highlights the evolving nature of cyber threats, with AI tools becoming the latest target. The potential consequences, including theft of sensitive data and manipulation of responses, underscore the importance of proactive measures to safeguard AI interactions.

Read also:

Latest