메뉴
HN
Hacker News 58일 전

구글 시트용 ChatGPT, 데이터 유출 취약점 발견

IMP
9/10
핵심 요약

OpenAI가 출시한 구글 시트용 ChatGPT 확장 프로그램에서 간접 프롬프트 인젝션(Indirect Prompt Injection) 공격을 통해 사용자의 스프레드시트 데이터가 외부로 유출될 수 있는 심각한 취약점이 발견되었습니다. 사용자가 자동 편집을 비활성화해도 공격이 실행되며, 악의적 스크립트를 통해 피싱(Phishing) 공격 및 다수의 통합 문서(Workbook) 유출이 가능합니다. 연구진의 책임 있는 공개(Responsible Disclosure)에도 불구하고 OpenAI가 이를 무시함에 따라 보안 위험이 알려지게 되었습니다.

번역된 본문

위협 인텔리전스(Threat Intelligence)

목차

구글 시트용 ChatGPT, 통합 문서를 유출하다

구글 시트용 ChatGPT는 단일 시트(Sheet) 내에서 간접 프롬프트 인젝션(Indirect Prompt Injection)이 발생할 경우, 피해자 계정 전체의 통합 문서(Workbook)에 영향을 미치는 데이터 유출(Data Exfiltration) 및 피싱 오버레이(Phishing Overlay) 공격에 취약합니다. 이 공격은 사용자가 설정에서 ChatGPT의 통합 문서 편집 전에 명시적으로 승인을 요구하도록 설정해 놓았더라도, 즉 사람의 개입(Human-in-the-loop) 승인 없이도 실행될 수 있습니다.

개요

최근 OpenAI는 구글 시트에서 ChatGPT를 사용할 수 있는 AI 확장 프로그램을 출시했으며, 출시 한 달도 채 되지 않아 185,000회 이상의 다운로드를 기록했습니다. 이 확장 프로그램을 통해 사용자는 사이드바에 있는 AI 챗봇과 상호 작용하여 스프레드시트를 조작할 수 있으며, ChatGPT 커넥터(Connector)의 데이터를 활용할 수 있는 이점도 있습니다.

정상적인 사용자의 단일 질문으로 인해 간접 프롬프트 인젝션 공격이 유발되면, 다음과 같은 모든 현상이 한 번에 발생할 수 있습니다:

  • 피해자 계정 전체의 수많은 통합 문서 유출
  • 대화형 피싱 팝업 표시
  • 전체 GPT 사이드바를 공격자가 제어하는 챗봇 인터페이스로 덮어쓰기
  • 공격자가 제어하는 사용자 통합 문서 편집

이 공격은 신뢰할 수 없는 데이터 소스(예: 가져온 시트 또는 ChatGPT 커넥터)가 ChatGPT를 조작하여 공격자가 제어하는 외부 스크립트를 실행할 때 발생합니다. 해당 스크립트는 사용자가 구글 시트용 ChatGPT 확장 프로그램에 부여한 권한(Permission)을 이용해 실행됩니다.

이 취약점은 OpenAI에 책임감 있게 제보(Responsible Disclosure)되었습니다. 그러나 수차례의 후속 조치에도 불구하고 최초 제보에 대한 자동 회신 외에는 어떠한 응답도 받지 못했습니다. OpenAI의 문서는 모델에 부여된 민감한 기능(예: 권한이 있는 스크립트 실행)이나 간접 프롬프트 인젝션을 통한 모델 조작의 위험성을 설명하지 못하고 대신 기능적 제한과 데이터 처리 문제에만 초점을 맞추고 있습니다. 따라서 우리는 이러한 위험에 대해 정보에 입각한 결정을 내릴 수 있도록 연구 결과를 공개합니다.

공격 체인(The Attack Chain)

  1. 사용자가 내부 재무 모델을 작업하고 있습니다.
  2. 사용자가 해당 모델에 사용할 외부 데이터 세트를 가져옵니다.
  3. 외부 시트에는 흰색 텍스트로 숨겨진 프롬프트 인젝션이 존재합니다.
  4. 사용자가 구글 시트용 ChatGPT에게 가져온 시트의 데이터를 재무 모델에 통합하도록 도움을 요청합니다.
  5. 주입된 프롬프트가 구글 시트용 ChatGPT를 조작하여 외부 스크립트를 실행하게 만듭니다. (참고: 구글 시트용 ChatGPT에는 에이전트 동작이 완료되기 전에 사용자의 승인이 필요한지 결정하는 '수정 사항 자동 적용(Apply edits automatically)'이라는 설정이 있습니다. 그러나 사용자가 자동 편집을 명시적으로 비활성화했더라도 이 공격은 성공합니다.)
  6. 외부 스크립트가 사용자의 통합 문서에서 재무 모델을 유출합니다. 아래에서 공격자의 서버 로그는 유출된 사용자의 재무 모델을 보여줍니다.
  7. 외부 스크립트는 훔친 데이터에서 다른 통합 문서로의 링크를 식별하고, 발견된 통합 문서를 유출하며, 찾을 수 있는 모든 통합 문서에 대해 이 과정을 계속 반복합니다. 여기서 내부 재무 모델 시트에는 예산과 관련된 다른 스프레드시트에 대한 링크가 포함되어 있었습니다. 악의적인 스크립트는 훔친 데이터에서 스프레드시트 URL을 식별하고 새로 발견한 통합 문서를 유출합니다. 그런 다음 훔친 데이터를 계속 처리하여 추가적인 통합 문서를 식별하고 유출하며, 결국 총 12개의 문서를 유출하게 됩니다. (참고: ChatGPT 사이드바에서 '중지' 버튼을 클릭해도 이미 실행이 시작된 스크립트가 완료되는 것을 막지는 못합니다.)

피싱 오버레이 공격(Phishing Overlay Attacks)

위에서 설명한 데이터 유출 외에도, 공격자가 제어하는 동일한 스크립트를 통해 악의적인 행위자는 두 가지 변형의 피싱 오버레이 공격을 수행할 수 있습니다.

변형 1: 공격자가 제어하는 사이트로 구글 시트용 ChatGPT 확장 프로그램 위에 사이드바가 열리며, 이를 통해 공격자는 확장 프로그램을 가장(Impersonate)할 수 있습니다. 악의적인 사이드바는 ChatGPT가 할 수 있는 것과 동일한 방식으로 시트를 편집하는 스크립트를 실행할 수 있습니다. 이를 통해 확장 프로그램이 정상적으로 수행하는 대부분의 작업을 수행할 수 있을 뿐만 아니라, 다음과 같은 악의적인 활동도 수행할 수 있습니다:

  • 모든 사용자 프롬프트 수집
  • 제공...(이하 원문 누락으로 인해 생략)
원문 보기
원문 보기 (영어)
Threat Intelligence Table of Content ChatGPT for Google Sheets Exfiltrates Workbooks ChatGPT for Google Sheets is vulnerable to data exfiltration and phishing overlay attacks that affect workbooks across the victim’s account after an indirect prompt injection in a single sheet. This attack does not require human-in-the-loop approvals, even when in settings the user has explicitly required human approval before ChatGPT edits workbooks. Overview Recently, OpenAI launched an AI extension for using ChatGPT in Google Sheets, which has accumulated over 185,000 downloads since its launch less than a month ago. This allows users to operate on their spreadsheets by interacting with an AI chatbot that lives in a sidebar, with the added benefit of drawing on data from ChatGPT connectors. A single indirect prompt injection attack triggered by a single benign user query can trigger all of the following effects at once: Exfiltration of many workbooks from across the victim’s account Display of an interactive phishing pop-up Overwriting the entire GPT sidebar with an attacker-controlled chatbot interface Attacker-controlled edits to your workbooks This attack occurs when any untrusted data source (e.g., from an imported sheet or ChatGPT connector) manipulates ChatGPT to run an attacker-controlled external script, which executes leveraging permissions the user has granted to the ChatGPT for Google Sheets extension. This vulnerability was responsibly disclosed to OpenAI. Despite multiple follow-ups, we received no communication beyond an automated reply to our initial disclosure. OpenAI's documentation fails to describe sensitive capabilities granted to the model (e.g., running privileged scripts) or risks of model manipulation via indirect prompt injection, instead focusing solely on functional limitations and data-handling concerns. As such, we are publishing our findings to enable informed decision-making regarding the risk surface. The Attack Chain A user is working on an internal financial model The user imports an external data set to use in their model The external sheet has a prompt injection hidden in white text. The user asks ChatGPT for Google Sheets to help integrate the data from the imported sheet into their financial model. The injection manipulates ChatGPT for Google Sheets to run an external script Note: ChatGPT for Google Sheets has a setting called ‘Apply edits automatically’ that determines when human approvals are required before an agentic action completes. However, this attack succeeds even when the user has explicitly disabled automatic edits. The external script exfiltrates the financial model from the user’s workbook Below, the attacker's server logs show the user’s exfiltrated financial model. The external script identifies links to other workbooks in the stolen data, exfiltrates the discovered workbooks, and continues across all workbooks it can find Here, the internal financial model sheet included a link to another spreadsheet relevant to budgeting. The malicious script identifies the spreadsheet URL in the stolen data and exfiltrates the newly discovered workbook. It then continues to process the stolen data, identifying and exfiltrating additional workbooks, eventually exfiltrating 12 in total. Note: Clicking the ‘stop’ button in the ChatGPT sidebar does not stop scripts that have started from finishing execution. Phishing Overlay Attacks In addition to the data exfiltration described above, the same attacker-controlled scripts enable a malicious actor to target two variants of a phishing overlay attack. Variant 1: A sidebar is opened that overlays the ChatGPT for Google Sheets extension with an attacker-controlled site, allowing the attacker to impersonate the extension. The malicious sidebar can execute scripts that edit the sheet in the same way ChatGPT can, allowing it to act in most of the ways the extension normally does, while also performing malicious activities such as: Harvesting all user prompts Providing the user with a misaligned chatbot to interact with Convincing the user to ‘reconnect’ connectors to gain access to additional apps Displaying a phishing UI to steal credentials for OpenAI Variant 2: A pop-up modal is opened that renders an attacker-controlled website to phish the user for credentials. Control Access to ChatGPT for Google Sheets Organizations can leverage the following configuration to control access to ChatGPT for Google Sheets: Workspace settings > Permissions & roles > ChatGPT for Excel and Google Sheets Responsible Disclosure This vulnerability was responsibly disclosed to OpenAI. Despite multiple follow-ups, we received no communication beyond an automated reply to our initial disclosure. OpenAI's documentation fails to describe sensitive capabilities granted to the model (e.g., running privileged scripts) or risks of model manipulation via indirect prompt injection, instead focusing solely on functional limitations and data-handling concerns. As such, we are publishing our findings to enable informed decision-making regarding the risk surface. Timeline May 08, 2026 PromptArmor discloses to OpenAI via email May 08, 2026 OpenAI sends an automated reply, confirming the intended reporting channel May 08, 2026 PromptArmor confirms email preference May 12, 2026 PromptArmor follows up May 18, 2026 PromptArmor follows up May 27, 2026 Public disclosure