| Summary | Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server. |
|---|---|
| Publication Date | Sept. 27, 2024, 3:15 a.m. |
| Registration Date | Sept. 27, 2024, noon |
| Last Update | Sept. 30, 2024, 9:46 p.m. |