chiprook
← Security
SecurityOctober 10, 2026, 13:25

OpenAI sets cross-site __obi cookie via ChatGPT advertiser pixels

A researcher reproduced how OpenAI's ad collector at bzr.openai.com sets a one-year __obi cookie with SameSite=None tied to a ChatGPT account, which is then sent back to OpenAI from ordinary sites running advertiser pixels. The check covered 936 pixels across 1,029 hostnames; the cookie also worked for logged-out users, and refusing marketing cookies did not stop it.

OpenAI sets cross-site __obi cookie via ChatGPT advertiser pixels
#OpenAI#ChatGPT
Read next
AI

OpenAI's __obi cookie tracks users after they leave ChatGPT

Security

CERT-UA: 100+ Hacked Sites Spread LunexStealer via Fake Cloudflare Checks

Security

ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw

Security

Hackers target WordPress sites via third-party WooCommerce plugin