• News/
  • https://www.zdnet.com/article/ai-chatbots-can-be-hijacked-to-steal-chrome-passwords-new-research-exposes-flaw/

AI chatbots can be hijacked to steal Chrome passwords - new research exposes flaw

ZDNet
·
Radhika Rajkumar
·
Published Mar 18, 2025
·
Updated

Generative AI has stirred up as many conflicts as it has innovations -- especially when it comes to security infrastructure. Enterprise security provider Cato Networks says it has discovered a new way to manipulate AI chatbots. On Tuesday, the company published its 2025 Cato CTRL Threat Report, which showed how a researcher -- who Cato clarifies had "no prior malware coding experience" -- was able to trick models, including DeepSeek R1 and V3, Microsoft Copilot, and OpenAI's GPT-4o, into creating "fully functional" Chrome infostealers, or malware that steals saved login information from Chrome. This can include passwords, financial information, and other sensitive details. Also: Navigating AI-powered cyber threats: 4 expert security tips for businesses "The researcher created a detailed fictional world where each gen AI tool played roles -- with assigned tasks and challenges," Cato's accompanying release explains. "Through this narrative engineering, the researcher bypassed the security controls and effectively normalized restricted operations." Step 1 of Cato's Immersive World jailbreaking approach. The new jailbreak technique, which Cato calls "Immersive World," is especially alarming given how widely used the chatbots that run these models are. DeepSeek models are already known to lack several guardrails and have been easily jailbroken, but Copilot and GPT-4o are run by companies with full safety teams. While more direct forms of jailbreaking may not work as easily, the Im...

Read full article

Affected Software

8 affected components
OpenAI GPT-4o
Microsoft Copilot
DeepSeek R1
DeepSeek V3
Cato Networks DeepSeek=R1
Cato Networks DeepSeek=V3
Microsoft Copilot
OpenAI GPT-4o
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in AI chatbots that can be exploited to steal passwords from Chrome.

2

What security implications are discussed?

The research highlights the potential risks of using AI chatbots in handling sensitive information, particularly passwords.

3

What products or software are affected?

The affected products include OpenAI's GPT-4o, Microsoft's Copilot, and DeepSeek's R1 and V3.

4

Who conducted the research on this AI vulnerability?

The research was conducted by Cato Networks, an enterprise security provider.

5

How can AI chatbots be hijacked to steal passwords?

The article explains that attackers can manipulate the behavior of AI chatbots to extract sensitive information like passwords.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203