Observed Signal · Jun 3, 2026 · Security Fix · Source: DEV Community · Impact: 4/5 · Sentiment: Negative

ChatGPT for Sheets Data-Exfiltration Bug Exposes AI Risks

Executive Signal Summary

Security firm PromptArmor published a disclosure on May 27, 2026 showing that the ChatGPT for Google Sheets extension (with over 185,000 downloads) could be induced to exfiltrate a user’s spreadsheets via a single ordinary-looking request. The exploit used an indirect prompt-injection technique: hidden instructions inside a sheet caused the assistant to fetch and run an external Apps Script, which used the extension's existing permissions to read the current workbook, follow links to other workbooks, and drain data (PromptArmor demonstrated exfiltrating 12 linked workbooks). The attacker then overlaid a fake chat UI to harvest further input. OpenAI shipped a fix on May 31, 2026 that removed the model’s ability to generate Apps Script code and said it would re-evaluate sandboxing and related functionality. The incident highlights a class of vulnerabilities when AI assistants process untrusted data as if it were control input.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major platform (OpenAI) shipped and patched a high-impact LLM integration vulnerability that enables data exfiltration; the incident reveals systemic risks for any product that attaches AI assistants to third-party data and will affect security, permissions design, and deployment practices across the industry.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • PromptArmor published a writeup on May 27, 2026 demonstrating data exfiltration from ChatGPT for Google Sheets.
  • ChatGPT for Google Sheets had more than 185,000 downloads at the time of disclosure.
  • The exploit used hidden (white-on-white) instructions in sheet data to trigger an external Apps Script that exfiltrated twelve linked workbooks.
  • OpenAI released a fix on May 31, 2026 removing the model's ability to generate Apps Script code.
  • The attack bypassed human-in-the-loop approval because the malicious actions occurred inside an external script running outside the approval flow.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 3, 2026
Original Coverage Title: “What the ChatGPT for Sheets data-exfiltration bug teaches about AI security”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

AI SecurityJul 24, 2026

Zenity Labs Reveals 'AgentForger' ChatGPT Vulnerability

Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that let attackers inject a malicious autonomous agent via a single phishing ChatGPT link. The forged agent could be created in the name of a clicked employee, inherit that employee's enterprise connectors (email, calendar, cloud storage, Slack/Teams) and existing authorizations without showing an OAuth consent screen, and be scheduled to repeatedly exfiltrate files, harvest credentials and MFA tokens, impersonate users, and persist inside the organization. Zenity Labs reported the issue to OpenAI via Bugcrowd on 2026-06-04; OpenAI acknowledged the report within a day and removed the vulnerable URL parameter within four days, patching the flaw before public disclosure. Zenity framed AgentForger as an evolution of CSRF and a new class of attacker-created, agentic insiders; exploitation in the wild is unknown.

Read assessment
Large Language Models (LLM) & AIMar 5, 2026

ChatGPT Revolutionizes Excel with Financial Data Integrations

OpenAI announced ChatGPT for Excel, a beta add‑in that embeds ChatGPT directly in Excel workbooks to build, update, and audit spreadsheet models using live formulas and workbook structure. The feature is powered by GPT‑5.4 (branded GPT‑5.4 Thinking), which OpenAI says is available in ChatGPT, Codex, and the API and has improved performance on finance workflows. OpenAI also added financial data integrations and partner apps (examples: FactSet, Dow Jones Factiva, LSEG, Daloopa, S&P Global, Moody’s, MSCI, Third Bridge, MT Newswires) and support for proprietary data via the Model Context Protocol (MCP). ChatGPT for Excel beta is available to Business, Enterprise, Edu, Teachers, K‑12, and to Pro/Plus users outside the EU; Enterprise workspaces include admin controls and security features (RBAC, SAML SSO, SCIM, audit logs, TLS/AES‑256, enterprise key management). OpenAI cites internal benchmark gains for GPT‑5.4 on investment‑banking tasks.

Read assessment
AI Agents SecurityAug 5, 2026

Google ADK Flaws Enable High‑Privilege AI Agent Actions

Security vulnerabilities in the Google Agent Development Kit (ADK) Python GitHub repository allowed public AI agents to trick automated workflows into performing high-privilege actions, including modifying pull requests and exposing credentials. Researchers from Pillar Security demonstrated multiple exploitation paths — a triage agent manipulated via crafted pull requests and prompt injection in public issues causing an analysis agent to run privileged fixing workflows. During testing, attackers could obtain a personal access token and a Google Cloud service account key. Google removed the problematic workflows in early July 2026 and deployed fixes for the remaining issue later that month after Pillar Security reported the findings.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.