Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ChatGPT Ad Tracking Cookie Raises Privacy Concerns

ChatGPT Ad Tracking Cookie Raises Privacy Concerns

Posted on September 21, 2026 By CWS

OpenAI’s Ad Tracking Mechanism Under Scrutiny

OpenAI’s advertising measurement system has come under scrutiny for employing a cross-site cookie that can associate activity on advertiser websites with a user’s ChatGPT account. This cookie, identified as __obi, is implemented when a user accesses ChatGPT, and can be returned to OpenAI when the user visits sites hosting OpenAI’s advertising pixel.

The mechanism has been independently tested on mobile devices and observed across 936 advertiser pixels on 1,029 hostnames. It mirrors the cross-site conversion tracking seen in major ad platforms, yet its link to an AI service introduces fresh privacy challenges.

Understanding the Ad Tracking Process

Upon accessing ChatGPT, a client generates a random identifier and requests a short-lived signed token from OpenAI’s backend. This token includes an account-linked subject value, an obi identifier, and a consent decision marked as analytics_allowed.

Subsequently, ChatGPT transmits the token to bzr.openai.com, an entity thought to be called “Bazaar,” which sets the __obi cookie for the .openai.com domain. The cookie’s configuration allows it to be part of cross-site requests, with a lifespan of up to one year, distinguishing it from other OpenAI cookies.

Impact on User Privacy

Advertisers using ChatGPT ads can add OpenAI’s measurement pixel to their sites. This pixel triggers code from OpenAI’s infrastructure, sending conversion data to bzr.openai.com. If a visitor already has the __obi cookie, it may automatically attach to those requests, enabling OpenAI to collect information about visited pages on third-party sites.

Data observed includes page paths related to medical conditions, financial solutions, and legal services. Additionally, the software retrieves data from advertiser pages, including hashed personal information like email addresses and phone numbers.

OpenAI’s Response and Future Implications

Despite OpenAI listing __obi as an analytics cookie rather than a marketing one, the issuance of sync tokens occurred when analytics consent was obtained, sometimes without marketing consent. This raises questions about data classification and consent handling.

OpenAI has acknowledged a privacy inquiry but has yet to provide detailed clarifications. The ongoing concerns highlight the need for transparency in digital advertising practices, particularly as they intersect with AI technologies.

As the digital landscape evolves, the balance between innovation and privacy will remain a critical focus, with implications for both technology developers and users worldwide.

Cyber Security News Tags:ad tracking, Advertising, ChatGPT, conversion tracking, Cookies, cross-site tracking, digital privacy, OpenAI, privacy concerns, user data

Post navigation

Previous Post: Noopur Davis: From Developer to Comcast’s Global CISO
Next Post: PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Related Posts

Top 10 Advanced Threat Detection Techniques for Modern Cybersecurity Top 10 Advanced Threat Detection Techniques for Modern Cybersecurity Cyber Security News
Researchers Details Masking Malicious Scripts and Bypass Defense Mechanisms Researchers Details Masking Malicious Scripts and Bypass Defense Mechanisms Cyber Security News
Hackers Launch ,000 Contest for Open-Source Attacks Hackers Launch $1,000 Contest for Open-Source Attacks Cyber Security News
11 Best SysAdmin Tools – 2025 11 Best SysAdmin Tools – 2025 Cyber Security News
F5 Addresses Critical Security Flaws in BIG-IP and NGINX F5 Addresses Critical Security Flaws in BIG-IP and NGINX Cyber Security News
Supply Chain Attack Targets art-template npm Package Supply Chain Attack Targets art-template npm Package Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data
  • ChatGPT Ad Tracking Cookie Raises Privacy Concerns
  • Noopur Davis: From Developer to Comcast’s Global CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data
  • ChatGPT Ad Tracking Cookie Raises Privacy Concerns
  • Noopur Davis: From Developer to Comcast’s Global CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark