3 ms·
Great work! Data leakage via untrusted third party servers (especially via image rendering) is one of the most common AI Appsec issues and it's concerning that
by wunderwuzzi23 1y ago
Great work!
Data leakage via untrusted third party servers (especially via image rendering) is one of the most common AI Appsec issues and it's concerning that big vendors do not catch these before shipping.
I built the ASCII Smuggler mentioned in the post and documented the image exfiltration vector on my blog as well in past with 10+ findings across vendors.
GitHub Copilot Chat had a very similar bug last year.
- diggan 1y ago> GitHub Copilot Chat had a very similar bug last year. Reminds me of "Tachy0n: The Last 0day Jailbreak" from yesterday: https://blog.siguza.net/tachy0n/ https://blog.siguza.net/tachy0n/ TLDR is: Security issue found, patched in a OS release, Apple seemingly doesn't do regression-testing so security researcher did, found that somehow the bug got unpatched in later OS releases.