ChatGPT for Google Sheets exfiltrates workbooks

Security, Vulnerabilities & Exploits(promptarmor.com)view on HackerNews
ChatGPTGoogle Sheetsdata exfiltrationphishingprompt injectionvulnerability

Author: hackerBanana

Date: 5/31/2026

Article Summary:
A vulnerability in the ChatGPT for Google Sheets extension allows for data exfiltration and phishing overlay attacks through indirect prompt injection, despite the user having explicitly required human approval before edits.