OpenAI’s ChatGPT Work Can Auto‑Login to Web Accounts Using Stored Cookies, Raising Credential Privacy Risks
What Happened – OpenAI’s new “ChatGPT Work” agent can sign in to a user’s web accounts by re‑using cookies created during an initial manual login. After the first authentication, the AI stores the session cookie and later accesses the same site without prompting the user for credentials.
Why It Matters for Compliance & Audit Readiness
- The feature creates a credential‑exposure vector that must be covered by SOC 2 CC6 (Logical Access) and privacy controls (GDPR/CCPA).
- Continuous evidence of how credential data is stored, consented to, and protected is essential for audit readiness; CookiePLUS can capture that evidence automatically.
- Demonstrating a documented policy for AI‑driven access and a defensible audit trail helps satisfy both security and privacy trust‑service criteria.
Who Is Affected – SaaS AI platforms, enterprise users of ChatGPT Work, and any organization that permits the agent to access internal or third‑party web applications (e.g., finance, HR, e‑commerce).
Recommended Actions –
- Review and restrict the sites you allow ChatGPT Work to access.
- Map the auto‑login behavior to SOC 2 CC6 and privacy controls; collect evidence of consent and cookie handling.
- Enforce MFA on all integrated accounts and monitor for anomalous AI‑initiated sessions.
- Update your privacy policy and DSAR processes to cover AI‑agent credential storage.
Source: ZDNet Security
Technical Notes – The AI uses the built‑in browser’s cookie store, similar to a standard web session. No CVE is involved, but the design creates a potential credential‑theft surface if cookies are intercepted or misused. The feature is limited to ChatGPT Pro/Plus accounts and currently works best in the Windows desktop client. Source: same as above