ChatGPT Frontend DOM Exposed: Unauthenticated Access Enables Automated Control
long_khan · reddit · 2026-08-12
A developer reported a potential frontend security issue in the web versions of ChatGPT and Claude.
- Vulnerability Details: The poster found that anyone can access and interact with the ChatGPT DOM using Playwright, even without being logged in.
- Potential Risks: Using Codex, developers can one-shot build a "mini-codex" without paying a dime. This exposes weak frontend protections that could be exploited for automated abuse or bypassing paywalls.
More from Safety
- Vercel CTO: Open-Weight Models Lack Guardrails, Everything Hackable Will Be Hacked — cramforce · 2026-08-12
- What People Actually Worry About Regarding AI Data Centers — iamrobotbear · 2026-08-12
- Securing AI Agents: Avoiding Persistent Credential Leaks — davidcrawshaw · 2026-08-12
- Will AI Compute Runs Dictate Global Economy? A Deep Dive into Anti-Capitalism and AI Control — jessi_cata · 2026-08-12
- Apollo Red-Teams Anthropic's Auto Mode, Cutting Classifier Miss Rate to 7% — MariusHobbhahn · 2026-08-12
- New USENIX Paper Achieves True Messenger Privacy via Math, Hiding Recipients from Server — matthew_d_green · 2026-08-12