ChatGPT Plus can exploit zero-day security vulnerabilities — why this should concern you

Cybercrime will soon be for the people.
 By 
Chance Townsend
 on 
A person's hand holds an iPhone with the OpenaAI ChatGPT app running GPT-4 visible
Credit: Smith Collection/ Gado / Contributor / Archive Photos

GPT-4, OpenAI's latest multimodal large language model (LLM), can exploit zero-day vulnerabilities independently, according to a study reported by TechSpot.

The study by University of Illinois Urbana-Champaign researchers has shown that LLMs, including GPT-4, can execute attacks on systems by utilizing undisclosed vulnerabilities, known as zero-day flaws. As part of the ChatGPT Plus service, GPT-4 has demonstrated significant advancements over its predecessors in terms of security penetration without human intervention.

The study involved testing LLMs against a set of 15 "high to critically severe" vulnerabilities from various domains, such as web services and Python packages, which had no existing patches at the time.


You May Also Like

GPT-4 displayed startling effectiveness by successfully exploiting 87 percent of these vulnerabilities, compared to a zero percent success rate by earlier models like GPT-3.5. The findings suggest that GPT-4 can autonomously identify and exploit vulnerabilities that traditional open-source vulnerability scanners often miss.

Why this is concerning

The implications of such capabilities are significant, with the potential to democratize the tools of cybercrime, making them accessible to less skilled individuals known as "script-kiddies." UIUC's Assistant Professor Daniel Kang emphasized the risks posed by such powerful LLMs, which could lead to increased cyber attacks if detailed vulnerability reports remain accessible.

Kang advocates for limiting detailed disclosures of vulnerabilities and suggests more proactive security measures such as regular updates. However, his study also noted the limited effectiveness of withholding information as a defense strategy. Kang emphasized that there's a need for robust security approaches to address the challenges introduced by advanced AI technologies like GPT-4.

Topics Cybersecurity

Headshot of a Black man
Chance Townsend
Assistant Editor, General Assignments

Chance Townsend is the General Assignments Editor at Mashable, covering tech, video games, dating apps, digital culture, and whatever else comes his way. He has a Master's in Journalism from the University of North Texas and is a proud orange cat father. His writing has also appeared in PC Mag and Mother Jones.

In his free time, he cooks, loves to sleep, and greatly enjoys Detroit sports. If you have any tips or want to talk shop about the Lions, you can reach out to him on Bluesky @offbrandchance.bsky.social or by email at [email protected].

Mashable Potato

Recommended For You

Florida man uses ChatGPT to sell his home. This is a real headline.
A pair of hands typing on a laptop as glowing images of houses float over their hands. The word "AI" glows in the middle.

How ChatGPT ends up in children's toys
A small robot, stuffed bear with OpenAI logo, and Grok toy.



Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!