Notion 3.0 AI agent exposes major security vulnerability; malicious PDFs can steal sensitive data

Notion 3.0 AI agent exposes major security vulnerability; malicious PDFs can steal sensitive data

1
With the release of Notion 3.0, its autonomous AI agent feature has garnered significant attention for its ability to automate tasks like document drafting and database updates. However, a recent report from cybersecurity firm CodeIntegrity reveals a serious security vulnerability in this feature, allowing attackers to trick the AI ​​agent into bypassing security protections and stealing data via malicious PDF files. This discovery has sparked widespread concern about the security of AI systems.

CodeIntegrity attributes the vulnerability to the AI ​​agent's "fatal trifecta"—a combination of a large language model (LLM), tool access permissions, and long-term memory. Researchers point out that traditional role-based access control (RBAC) is insufficiently protective in such complex environments. The core vulnerability lies in Notion 3.0's built-in "functions.search" web search tool. While originally designed to help the AI ​​obtain external information, it has become a gateway for data leakage.

To verify the vulnerability's severity, the CodeIntegrity team conducted a demonstration attack: they created a PDF file containing hidden malicious instructions. When a user uploaded it to Notion and asked the AI ​​to "summarize the report," the agent executed the instructions, uploading sensitive data to the attacker's server. Shockingly, the attack succeeded even with the advanced Claude Sonnet 4.0 language model, highlighting a fundamental flaw in existing protections.

Even more worryingly, this vulnerability isn't limited to PDF files. Because Notion 3.0 AI agents can connect to third-party services like GitHub, Gmail, and Jira, any of these integrations could potentially serve as a vector for indirect prompt injection. This means malicious content could be infiltrated through various channels, tricking the AI ​​into performing actions contrary to the user's intent. This discovery serves as a wake-up call for the AI ​​security community, urging developers to urgently reevaluate the security architecture of intelligent agents.

Aceii One robot replaces tennis coach

Robotic applications are gradually expanding beyond factories into tennis. Aceii One is both a serving machine and a sophisticated coach powered by artificial

Aceii One robot replaces tennis coach

Samsung will upgrade its smartphone cameras with the release of One UI 8.5

Samsung is testing new camera features that may be released with One UI 8.5. According to firmware leaks from enthusiasts, the default video editor will now su

Samsung will upgrade its smartphone cameras with the release of One UI 8.5

‌2025 Flagship Chip Showdown: Qualcomm Snapdragon 8 Extreme Edition vs. Dimensity 9500 Full Comparison

Today, tech media outlet Android Headline released an in-depth comparison, revealing a head-to-head battle between the two core Android flagship chipsets of 20

‌2025 Flagship Chip Showdown: Qualcomm Snapdragon 8 Extreme Edition vs. Dimensity 9500 Full Comparison

OpenAI releases GPT-5-Codex model API: Revolutionary improvement in programming efficiency

OpenAI today officially launched an API for its latest AI model, GPT-5-Codex, which demonstrates groundbreaking capabilities in programming. The model maintain

OpenAI releases GPT-5-Codex model API: Revolutionary improvement in programming efficiency

MediaTek releases Dimensity 7360 processor: setting a new benchmark for the mid-range market with 200 million pixels and gaming optimization

MediaTek recently officially launched the Dimensity 7360 processor, targeting the mid-range market. With features such as an octa-core design, 200-megapixel su

MediaTek releases Dimensity 7360 processor: setting a new benchmark for the mid-range market with 200 million pixels and gaming optimization

NVIDIA Open Sources Audio2Face Model: Revolutionary Breakthrough in Game and Film Character Animation

NVIDIA recently announced the open source release of its generative AI facial animation model, Audio2Face. This technology analyzes acoustic features such as p

NVIDIA Open Sources Audio2Face Model: Revolutionary Breakthrough in Game and Film Character Animation

Intel Seeks Apple Investment: Semiconductor Foundry Cooperation May Become a New Focus

After securing investments from SoftBank, the US government, and Nvidia, Intel, led by Lip-Mou Tan, is accelerating its external partnerships. Bloomberg report

Intel Seeks Apple Investment: Semiconductor Foundry Cooperation May Become a New Focus

Qualcomm will hold the Snapdragon Summit today and is expected to release the Snapdragon 8 Elite Gen 5

According to official news, Qualcomm will hold the first day of its 2025 Snapdragon Summit on September 24th, focusing on the launch of its next-generation fla

Qualcomm will hold the Snapdragon Summit today and is expected to release the Snapdragon 8 Elite Gen 5

Huawei will release two new wearable products today: WATCH GT6 + FreeClip 2

According to official information, Huawei Device will hold a wearable and audio product launch event at 2:30 PM on September 24th, unveiling the new Huawei WAT

Huawei will release two new wearable products today: WATCH GT6 + FreeClip 2

The era of AI crime has arrived: Hackers use generative technology to launch cyberattacks

While many companies are still exploring the application scenarios of generative AI, criminal organizations have already thoroughly weaponized it. Recent secur

The era of AI crime has arrived: Hackers use generative technology to launch cyberattacks

iPhone 17 series first sales data exposed: Standard version reaches 185% of the previous generation

Apple's latest iPhone 17 series has officially launched its first sales, and its market performance has far exceeded expectations. Data from an e-commerce

iPhone 17 series first sales data exposed: Standard version reaches 185% of the previous generation

Huawei nova Flip S color and memory versions leaked: 6 colors + up to 1TB

Recently, detailed specifications for Huawei's new small foldable phone, the nova Flip S, have been leaked online. According to a digital blogger and infor

Huawei nova Flip S color and memory versions leaked: 6 colors + up to 1TB

Xiaomi Mi 17 Pro series debuts the Shadow Hunter 950L sensor, codenamed the King of Backlight

On September 24th, Xiaomi officially announced that its new flagship Xiaomi 17 Pro series, codenamed "King of Backlight," will be released at 7 PM on the 25th

Xiaomi Mi 17 Pro series debuts the Shadow Hunter 950L sensor, codenamed the King of Backlight

OPPO Watch S officially announced its global debut on October 16th! Focusing on the concept of lightness and thinness

On September 24th, OPPO announced on its official Weibo account that the OPPO Watch S smartwatch will debut globally on October 16th. According to official inf

OPPO Watch S officially announced its global debut on October 16th! Focusing on the concept of lightness and thinness

Qualcomm CEO: 6G pre-commercial equipment will be widely deployed as early as 2028

On September 24th, at the 2025 Snapdragon Summit, Qualcomm President and CEO Cristiano Amon stated that 6G pre-commercial equipment will be deployed on a large

Qualcomm CEO: 6G pre-commercial equipment will be widely deployed as early as 2028