• News/
  • https://www.theregister.com/2025/08/19/ollama_driveby_attack/

Ollama bug allows drive-by attacks - patch now

The Register
·
Jessica Lyons
·
Published Aug 19, 2025
·
Updated

A now-patched flaw in popular AI model runner Ollama allows drive-by attacks in which a miscreant uses a malicious website to remotely target people's personal computers, spy on their local chats, and even control the models the victim's app talks to, in extreme cases by serving poisoned models. GitLab's Security Operations senior manager Chris Moberly found and reported the flaw in Ollama Desktop v0.10.0 to the project's maintainers on July 31. According to Moberly, the team fixed the issue within hours and released the patched software in v0.10.1 — so make sure you've applied the update because Moberly on Tuesday published a technical writeup about the attack along with proof-of-concept exploit code. "Exploiting this in the wild would be trivial," Moberly told The Register. "There is a little bit of work to build the proper attack infrastructure and to get the interception service working, but it's something an LLM could write pretty easily." The good news: the vulnerable component is a new web service powering the GUI app — not the core Ollama API. Since the new GUI isn't as well known, and was only available for a few weeks before Moberly found and reported the bug, it's likely that miscreants didn't have sufficient time to poke holes in it and exploit the flaw on their own. "There's no evidence it was exploited in the wild," Moberly said. "Hopefully everyone is able to patch before that happens. Those who installed via the official application installers receive auto-upd...

Read full article

Affected Software

2 affected components
ollama Desktop=0.10.0
ollama Desktop=0.10.1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203