Thursday, March 28th 2024

NVIDIA Issues Patches for ChatRTX AI Chatbot, Suspect to Improper Privilege Management

Just a month after releasing the 0.1 beta preview of Chat with RTX, now called ChatRTX, NVIDIA has swiftly addressed critical security vulnerabilities discovered in its cutting-edge AI chatbot. The chatbot was found to be susceptible to cross-site scripting attacks (CWE-79) and improper privilege management attacks (CWE-269) in version 0.2 and all prior releases. The identified vulnerabilities posed significant risks to users' personal data and system security. Cross-site scripting attacks could allow malicious actors to inject scripts into the chatbot's interface, potentially compromising sensitive information. The improper privilege management flaw could also enable attackers to escalate their privileges and gain administrative control over users' systems and files.

Upon becoming aware of these vulnerabilities, NVIDIA promptly released an updated version of ChatRTX 0.2, available for download from its official website. The latest iteration of the software addresses these security issues, providing users with a more secure experience. As ChatRTX utilizes retrieval augmented generation (RAG) and NVIDIA Tensor-RT LLM software to allow users to train the chatbot on their personal data, the presence of such vulnerabilities is particularly concerning. Users are strongly advised to update their ChatRTX software to the latest version to mitigate potential risks and protect their personal information. ChatRTX remains in beta version, with no official release candidate timeline announced. As NVIDIA continues to develop and refine this innovative AI chatbot, the company must prioritize security and promptly address any vulnerabilities that may arise, ensuring a safe and reliable user experience.
Sources: NVIDIA, via Tom's Hardware
Add your own comment

6 Comments on NVIDIA Issues Patches for ChatRTX AI Chatbot, Suspect to Improper Privilege Management

#1
ThrashZone
Hi,
The wonders of AI new security holes hehe :laugh:
Posted on Reply
#2
P4-630
Hey AI, got any other ways to hack you?...
Posted on Reply
#3
ThrashZone
P4-630Hey AI, got any other ways to hack you?...
Response would likely be
AI didn't get hacked your system did then 10+ pages of blah.... hehe
Posted on Reply
#4
Darmok N Jalad
I guess the AI wasn’t programmed to recognize that it had too many privileges.
Posted on Reply
#5
ThrashZone
Hi,
Yeah it's not really AI if it can't point out it's own security flaws :slap:
Posted on Reply
#6
RayneYoruka
Well this comes in hand as I was about to start using it (or more like what can I do with it)
Posted on Reply
Apr 28th, 2024 05:05 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts