Updated
Updated · ZDNet · Aug 27
ChatGPT Adds Cookie-Based Auto Login for Pro and Plus Accounts, Raising Session-Security Risks
Updated
Updated · ZDNet · Aug 27

ChatGPT Adds Cookie-Based Auto Login for Pro and Plus Accounts, Raising Session-Security Risks

2 articles · Updated · ZDNet · Aug 27

Summary

  • Tuesday’s update lets ChatGPT Work keep users signed in to password-protected sites by storing session cookies in its built-in browser, so later tasks can access those accounts without another login prompt.
  • The feature is limited to Pro and Plus accounts and still requires the first sign-in to be entered manually or via a password manager; users can review and delete saved cookies in Settings under Cloud Browser.
  • ZDNET found the capability worked in the ChatGPT Windows app with Amazon and eBay, but Amazon blocked attempts from the web version and later rejected some repeated Windows-app sessions.
  • OpenAI says the model cannot see usernames or passwords and asks for confirmation before consequential actions, but security experts warned the bigger risk is an AI agent operating inside an authenticated session.
  • Security advisers recommended starting with low-stakes sites and avoiding finance or healthcare accounts until OpenAI provides clearer details on how persistent access is protected, reviewed and revoked.

Insights

If an AI holds your session cookies, could a hidden prompt on a random webpage secretly drain your accounts?
When an AI agent goes rogue using your saved login, who is legally responsible for the resulting damage?