A plug-in in the ChatGPT desktop app reads and searches your iMessage, SMS and RCS threads and sends messages through Messages on your behalf. By default nothing goes out until you approve both the text and the recipients. There is a switch that removes that step, and OpenAI's own documentation argues against using it.
Researchers at Adversa hid a prompt injection as ciphertext with the key next to it. Grok decrypted it in its own sandbox and sent the user's name, location, and chat history to an attacker's server, without a warning and without asking.
On August 19, OpenAI released a preview of a system that recognizes abuse patterns across several linked sessions without retaining user content. The idea is that only a narrowly defined safety signal is passed on, without exposing the prompts and responses themselves, which keeps the zero data retention guarantee for paid API customers in force. The target is attackers who split a request across several conversations to avoid detection. The approach is the opposite of Anthropic's policy, which keeps data for 30 days with controlled human review; if you are choosing a vendor for a project with sensitive client data, that difference is worth understanding before you sign. Wider rollout and a technical paper were announced for September.