New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html

https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html

ONE SENTENCE SUMMARY:

OpenAI’s ChatGPT Lockdown Mode reduces prompt-injection data exfiltration risk by restricting networked tools, while adding session management controls.

MAIN POINTS:

  1. Introduces optional Lockdown Mode for eligible personal accounts to mitigate prompt-injection exfiltration.
  2. Targets users handling sensitive data needing stronger protection guarantees.
  3. Available across Free, Go, Plus, Pro, and self-serve Business plans.
  4. Limits tools connecting to web or external services to reduce outbound data leakage.
  5. Builds on sandboxing and controls against URL-based exfiltration techniques.
  6. Focuses on removing exfiltration pathways, not preventing prompt injections outright.
  7. Leaves memory, file uploads, and conversation sharing behavior unchanged.
  8. Disables or restricts browsing, images, deep research, agent mode, canvas networking, and downloads.
  9. Mutually exclusive with Developer Mode; enabling one automatically disables the other.
  10. Adds session review/logout feature with device, app, location, timing, and trust indicators.

TAKEAWAYS:

  1. Activate Lockdown Mode when sensitive data exposure would be high impact.
  2. Expect reduced functionality as a tradeoff for fewer outbound exfiltration routes.
  3. Recognize residual risk from apps, capability combinations, or novel techniques.
  4. Understand prompt injections can still manipulate outputs even without data theft.
  5. Use new session-management tooling to detect and respond to account compromise quickly.