Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsIn a September 2024 security demonstration, researcher Johann Rehberger showed that malicious instructions hidden in untrusted content could lead ChatGPT to save incorrect information or instructions in its long-term memory. The demonstration did not establish that ChatGPT has human-like memories, or that the same vulnerability still works today.
What “false memories” meant in the ChatGPT demonstration
The phrase refers to information or instructions stored in ChatGPT’s memory that were inaccurate or malicious—not to human-style autobiographical memory. ChatGPT memory is a product feature that can retain details and use them in later conversations.
In 2024, Rehberger demonstrated how untrusted content processed by ChatGPT could carry instructions that affected what the system stored. Ars Technica described the issue as an indirect prompt injection: rather than typing the malicious instruction directly, an attacker places it in content the model is asked to process. The research paper describes this broader pattern as persistent prompt injection. Ars Technica’s report and the research paper document the attack concept and proof of concept.
How indirect prompt injection could affect memory
- ChatGPT encounters untrusted content. This could be a document or other material supplied for the model to process.
- The content includes instructions aimed at the model. If the model treats those instructions as actionable rather than as data to analyze, they can influence its behavior.
- The model saves information or instructions. The 2024 demonstration showed this could place incorrect information or malicious instructions in long-term memory.
- The stored item can affect later chats. Because memory is intended to inform future conversations, a planted item could persist beyond the exchange in which the model encountered it.
This is a security issue involving how a model handles untrusted input and persistent memory; it is not evidence of a measured rate at which users’ memories are altered. The sources describe a proof of concept, not a prevalence study.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Memory manipulation and data exfiltration were separate risks
Rehberger’s attack scenario also explored sending data to an outside destination. That exfiltration path was a related consequence, but it is distinct from planting persistent instructions or incorrect information in memory. The 2024 reporting said OpenAI had mitigated the exfiltration vector while the researcher said the memory-write concern remained at that time. That is a historical account, not confirmation of the vulnerability’s status today. Futurism’s September 29, 2024 report describes the demonstration and quotes Rehberger: “The prompt injection inserted a memory into ChatGPT’s long-term storage.”
How to review, change, or remove ChatGPT memories
OpenAI’s current Help Center explains that users can review and manage saved memories, correct remembered information, and turn memory features off. Labels and availability can vary by account and may change. Follow the current instructions in OpenAI’s Memory FAQ.
Rank #2
- Review or correct a memory: Use ChatGPT’s memory controls to see what it has saved and ask it to update incorrect details, or manage the items in settings.
- Remove a saved memory: Delete the memory itself through the memory controls. Deleting only the conversation where the detail appeared may leave a separately saved memory in place.
- Remove the source conversation too: OpenAI says full removal may require deleting both the saved memory and the chat in which the information was shared.
- Turn off memory references: Settings may offer controls for saved-memory use and for referencing chat history. Turning a feature off changes future use; it is not the same action as deleting existing saved memories.
- Use Temporary Chat for a conversation that should not use or update memory: OpenAI recommends Temporary Chat when you do not want a conversation to use or update memory. See OpenAI’s Temporary Chat FAQ for current behavior and availability.
Does deleting a chat erase its memory?
Not necessarily. A saved memory can be stored separately from the conversation that supplied the information, so deleting that chat alone may not remove the saved item. To remove both, use the memory controls to delete the saved memory and delete the source conversation as well, following OpenAI’s current guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is the 2024 vulnerability still present?
The cited reporting and OpenAI help documentation do not establish whether the same exploit Rehberger demonstrated in 2024 remains possible in the current ChatGPT product. The demonstration should be understood as a historical security finding, not as a current reproduction or a guarantee that today’s memory controls prevent every prompt-injection attack.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

