Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenAI patched the ChatGPT vulnerabilities described in SecurityWeek’s March 29, 2023 report the week before it was published. The reported flaws involved web cache deception and a bypass that could expose account information or conversations. The report is historical; it does not show that those vulnerabilities remain exploitable today.

What the March 2023 report described

SecurityWeek reported that the first vulnerability was a web cache deception flaw. A crafted, CSS-like URL path could target a ChatGPT session endpoint. If an attacker persuaded someone to open the link and the response was cached, account-related information—including names, email addresses and access tokens—could be exposed, according to the report. SecurityWeek attributed discovery to Gal Nagli, then identified as Shockwave’s CEO and founder.

SecurityWeek said OpenAI initially addressed the issue by adding a regular-expression rule telling its caching server not to cache the endpoint. During analysis of that fix, researcher and CISO Ayoub Fathi reportedly found a bypass that exposed conversation titles through another ChatGPT API. Further analysis produced a payload that bypassed the original fix and could potentially expose titles, full conversations and account status across ChatGPT APIs. The article says Fathi worked with OpenAI to address the issues.

These are reported potential exposures, not evidence that accounts were actually abused. The reviewed reporting does not establish how many accounts may have been affected, whether the flaws were exploited in the wild, or a CVE identifier.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Did OpenAI patch the vulnerabilities?

Yes. SecurityWeek’s March 29, 2023 article said OpenAI had patched the reported issues the previous week, including the bypass discovered during analysis of the initial fix. The report does not establish that the vulnerabilities remain open, so it should not be read as a warning that the same 2023 flaws are currently exploitable.

The report appeared shortly after a March 2023 ChatGPT service interruption associated with an issue in an open-source Redis client. That outage was a separate event, not the cache-deception vulnerability.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A separate account-takeover disclosure in 2026

A later incident should not be conflated with the 2023 report. In a September 13, 2026 write-up, Hacktron described a different chain that its authors said they exercised in July 2026: a libheif heap-buffer-overflow route through image uploads on OpenAI’s community forum combined with an OpenAI single-sign-on misconfiguration. Hacktron said the chain could reach ChatGPT and Codex accounts.

Hacktron said it demonstrated impact with a harmless pull request in an internal repository and then stopped testing. Its report says OpenAI confirmed its side of the issue was fixed roughly 14 hours after the initial submission. Hacktron later reported a $6,500 bounty for the OpenAI-side finding; it said the award excluded testing against the Discourse-hosted forum. That figure concerns Hacktron’s separate 2026 disclosure, not the 2023 vulnerabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Disclosure Reported issue Reported impact Researcher and remediation
SecurityWeek, March 29, 2023 Web cache deception in ChatGPT APIs, followed by a bypass of the initial fix Potential exposure of account details, conversation titles, full conversations and account status SecurityWeek named Gal Nagli for the initial issue and Ayoub Fathi for the bypass analysis; it said OpenAI addressed the issues the prior week.
Hacktron, September 13, 2026 (describing testing in July 2026) Community-forum image-processing flaw chained with an OpenAI SSO misconfiguration Hacktron said the chain could reach ChatGPT and Codex accounts Hacktron said OpenAI fixed its side roughly 14 hours after the initial submission; it reported a later $6,500 bounty for the OpenAI-side finding.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you see unrecognized activity

For current account protection and recovery, follow OpenAI’s Help Center guidance rather than treating the 2023 disclosure as evidence of a present breach. OpenAI recommends a strong, unique password and multi-factor authentication (MFA). It cautions that enabling MFA does not end sessions that are already active.

  1. Change a compromised password. If you sign in with Google or Microsoft, reset the password for that identity-provider account. OpenAI says current sessions are logged out within 30 minutes after a password change.
  2. Log out all sessions. In ChatGPT, open Settings > Security and use the session-management controls. OpenAI says logging out all sessions can take up to 30 minutes to reach other ChatGPT sessions.
  3. Review account activity. Check Settings > Security for Security history and Active sessions. If you use the API, delete API keys you do not recognize and inspect API usage.
  4. Enable MFA after securing access. OpenAI’s guidance for suspected unauthorized access says to change the compromised password and log out all sessions before enabling MFA.
  5. Contact OpenAI Support if suspicious activity continues or you cannot secure the account.

OpenAI’s current security guidance also describes Advanced Account Security for eligible consumer ChatGPT accounts; it is unavailable to Enterprise users, enterprise-managed accounts and accounts tied to an enterprise-managed domain. The same guidance mentions an OpenAI + Yubico hardware security key bundle for eligible users. These are optional current sign-in protections, not fixes for the historical server-side vulnerabilities.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.