字号 ·· | 护眼
连线

ChatGPT的Mac应用存在一个漏洞,可能让黑客获取敏感数据A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

点「原文对照」整页切到原文,或双击某段只看那段的原文。

该漏洞可能被攻击者利用,从而完全控制受害者的计算机上的 ChatGPT 应用程序。攻击者将能够访问该应用程序存储的所有聊天记录及其他数据,以及浏览器会话等关联信息。这一安全漏洞由 Objective-See 基金会的研究人员发现,它揭示了人工智能平台为正常运行所需被赋予的深度系统访问权限——同时也暴露了这些平台所面临的安全风险。

The bug could have been exploited to essentially take over ChatGPT on a victim’s computer, giving an attacker access to all the chat logs and other data stored by the app, as well as interconnections like browser sessions. Discovered by researchers at the Objective-See Foundation, the vulnerability illustrates the deep system access and trust that AI platforms are afforded in order to work—and the target that this puts on their backs.

“这些应用程序需要大量的系统访问权限才能完成它们的工作,”Objective-See 基金会的软件分析师、长期从事 macOS 研究的帕特里克·沃德尔(Patrick Wardle)解释道:“它们就像大楼的管理员,拥有所有房间的钥匙;如果这些‘管理员’被恶意操控,后果将非常严重——因为这意味着未经授权的代码也可能获得对系统所有资源的访问权限。”

“Agents need a lot of access to do their job,” says Objective-See Foundation software analyst and longtime macOS researcher Patrick Wardle. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”

OpenAI 于 9 月 25 日在其系统更新日志中公开承认了这一安全问题,并立即进行了修复。OpenAI 的发言人谢恩·鲍尔(Shane Bauer)在接受《WIRED》杂志采访时表示:“我们一直在不断改进我们的安全措施,但也意识到需要加快改进的步伐。”

OpenAI publicly acknowledged the security flaw and fix in its system change log on September 25. “We continue to evolve our security practices, but recognize a need to move faster,” OpenAI spokesperson Shane Bauer told WIRED in a statement.

ChatGPT 的 macOS 应用程序包含多个相互通信的组件,这些组件通过数字签名来确保通信的安全性。这些签名验证机制用于确认发起请求的组件确实是 OpenAI 自己开发的,而非来自外部的恶意软件。系统设计甚至要求在请求的传输过程中进行三层签名验证,以确保恶意软件无法伪装成 OpenAI 的组件,从而发起看似合法的请求。

The ChatGPT macOS app includes multiple components that communicate with each other securely by checking for digital signatures. The idea is to confirm with these validity checks that both processes are OpenAI components and not outside, potentially malicious software making a request. And the system design goes so far as to require these signature checks at three layers of remove from the request, to ensure that malicious software isn’t somehow directing an OpenAI component to be a proxy and make a seemingly trusted request.

关键发现: Foundation的研究人员发现,存在一个可被利用的组件——即一个脚本解释器。该组件能够接收未经验证的脚本(或需要执行的命令列表),并可能被恶意者操控,从而将这些脚本注入到 ChatGPT 的核心处理流程中。Wardle 表示:“虽然系统会检查相关进程的父进程和祖父进程,但恶意脚本只需多次创建该脚本解释器,然后发起请求即可满足攻击者的要求。”

Objective-See Foundation researchers found, though, that there is a trusted component, a script interpreter, that would accept an untrusted script (or list of commands to run) and could then be manipulated to deliver this script into the main ChatGPT process. “They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” Wardle says.

他补充说,这个漏洞的利用方式极其简单;他的概念验证实验仅使用了大约十几行代码。除了能够访问 ChatGPT 的聊天记录外,该漏洞还可以被用来让 ChatGPT 执行攻击者的指令(例如打开浏览器或其他敏感应用程序),而这些操作会伪装成 OpenAI 软件发出的合法指令。

The vulnerability was “insanely trivial” to exploit, he adds, and his proof of concept only required about a dozen lines of code. In addition to accessing ChatGPT chat logs, the vulnerability could also be used to get ChatGPT to run commands for the attacker, such as accessing a browser or other sensitive applications, with the requests appearing as legitimate instructions issued by the OpenAI software.

Wardle 将在 11 月举行的专注于苹果产品的安全会议 Objective by Sea 上,展示他对多个 AI 应用程序漏洞的分析结果。

Wardle will present analysis of a number of AI macOS application bugs at Objective by the Sea, an Apple-focused security conference in November.

最近,他还发现了 Meta 公司新推出的 Muse AI 助手中的语音识别功能中的一个漏洞(该漏洞已被修复)。该漏洞可能被本地攻击者利用来获取用户的认证令牌,从而窃取用户数据。此外,他还向 OpenAI 提交了另一项关于 ChatGPT 与该公司新推出的始终处于运行状态的 Dots AI 助手之间集成问题的漏洞报告,OpenAI 目前正在审查他的报告。

He recently found a flaw, now patched, in the dictation feature of Meta’s new Muse AI assistant that could have been exploited by a local attacker to grab a mishandled authentication token and gain access to user data. And he says that he has already submitted a new vulnerability finding to OpenAI related to the integration between ChatGPT and the company’s new always-on Dots AI assistant. OpenAI is currently reviewing his report.

Wardle 指出:“目前,AI 公司都过于专注于添加新功能,但事实证明:功能越多,攻击面也就越大。因此,所有这些公司都必须高度重视安全性问题——然而从实际情况来看,安全性往往仍被忽视。”

“AI companies are fixated on adding features right now,” Wardle says. “But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”