OpenAI Logout Glitch: When “Log Out of All Sessions” Didn’t Log Me Out


Affected Feature

OpenAI's "Log out of all sessions" feature. This is supposed to sign you out from every device where you're logged in - web, mobile, everything.

How to Reproduce

  1. Log into OpenAI on desktop browser and mobile app with the same account
  2. On desktop, click "Log out of all sessions" in account settings
  3. Wait about 30 minutes
  4. Open the mobile app
  5. You're still logged in - no re-authentication required
  6. Even force-closing and reopening the app doesn't trigger a logout

The web session ends properly, but the mobile app session stays active even though you explicitly logged out everywhere.

Company Response

Reported via Bugcrowd. Marked as duplicate since another researcher found it first, but OpenAI confirmed and fixed the issue as of June 4, 2025.

Comments

Popular posts from this blog

When an AI Search Engine Forgot Who It Was: A Bug Report That Changed Perplexity AI’s Identity

Understanding Android’s One-Time Permissions and Their Privacy Implications

Your Android Phone's Dirty Little Secret - Gemini