ChatGPT's __obi cookie links your browsing on other sites to your OpenAI account, researcher finds
机器之心 · wechat · 2026-09-21
- Security researcher buchodi reverse-engineered OpenAI's ad platform ("bazaar"): ChatGPT plants a obi cookie (SameSite=None, one-year expiry) that gets sent back to OpenAI from any site running its ad pixel — even the script-load request itself carries it.
- The SDK auto-collects far more than advertisers pass in (685 vs 255 observed events), hashing emails/phones but sending location and ZIP in plaintext; URL paths alone exposed medical, debt and lawsuit pages. Of 932 sync tokens, 736 tied to logged-in accounts; anonymous IDs are per-device and stable for 27+ days, so logged-out users are trackable too.
- Verified across 936 ad pixels and 1,029 hostnames; one of the author's obi values was sent from 12 sites including Chewy, Wayfair and Coursera. Context: ChatGPT ads launched Feb 2025 ($60 CPM, $200K minimum), expanded to 31 European countries, and a California class action over Meta/Google pixels was filed in May.
Related event: ChatGPT Accused of Cross-Site Tracking via __obi Cookie(3 posts)→
More from Safety
- India Needs Independent AI Measurement Capacity, IIT Madras Scholars Argue — ravi_iitm · 2026-09-21
- Handing my tax credentials to an AI agent: great UX, unsettling security — zeeg · 2026-09-21
- Roblox CEO proposes US ban on paying licensing fees to Chinese AI companies — robleclerc · 2026-09-21
- ZuckOff App Detects Nearby Meta Smart Glasses via Bluetooth Fingerprints, Tops 5,000 Downloads — LexiLove · 2026-09-21
- New paper: simple difference-of-means vectors detect reward hacking from LLM internals before it happens — burny_tech · 2026-09-21
- DeepSeek Web Output Style Reportedly Lobotomized by Safe Harbor RLHF — Old_Let6328 · 2026-09-21