The most striking AI privacy story of the past few weeks was not a vulnerability or a P0 incident. It was a cookie written into OpenAI's own published cookie policy, configured explicitly to be carried across sites.

The Sept 20 disclosure

Independent researcher Jamie Larson published a long-form writeup on Buchodi Threat Intel on September 20, detailing how the ad collector at bzr.openai.com writes a cookie called __obi. Scope: .openai.com. Lifetime: one year. SameSite=None; Secure. That combination is the only configuration that lets a browser send a cookie on cross-site requests, and every other identifier in OpenAI's policy is configured SameSite=Lax or scoped to a domain that prevents the cross-site trip.

The researcher reproduced the full chain on his own phone, verified it with two independent capture methods, and cross-checked it against 23,929 requests across 936 advertiser pixels on 1,029 hostnames. When a user later visits a site that has installed OpenAI's advertiser pixel, the cookie is attached to the pixel's request back to OpenAI's ad infrastructure. OpenAI can connect the user's behavior on those sites — products searched, articles read, purchases made — back to the ChatGPT account.

The mechanism, step by step

Step 1: the client on chatgpt.com generates 16 random bytes and calls /backend-api/bazaar/obi/sync-token. OpenAI's backend returns an RS256 JWT containing the account's sub field, an obi identifier, and a 60-second expiry. The issuer is chatgpt-wadi; the audience is bzr.openai.com (bzr is OpenAI's internal name for its ads platform).

Step 2: that JWT is POSTed cross-site to bzr.openai.com/v1/obi/sync, and the response sets __obi on .openai.com with Max-Age=31536000 and SameSite=None; Secure.

Step 3: any subsequent request from an advertiser site to OpenAI's ad infrastructure — including simply loading the pixel's