ChatGPT Flaw Allowed Hidden Cross-Account Gmail Data Theft, Now Patched
Check Point security researchers discovered a vulnerability in ChatGPT's code execution environment that allowed attackers to silently extract data from a victim's connected Gmail account without any visible indication to the user. The flaw exploited a shared internal service — backed by JFrog's Artifactory — that was supposed to isolate user containers but instead allowed metadata to be written and read across accounts, effectively creating a covert communication channel. An attacker could inject a hidden instruction into a victim's session, causing ChatGPT to fetch Gmail data and relay it back, while the victim's conversation appeared completely normal. OpenAI has since patched the vulnerability and shut down the related service, though researchers noted the same shared infrastructure was also linked to a separate Hugging Face intrusion disclosed by OpenAI. Security analysts warn the incident highlights a broader risk pattern for organizations integrating AI with internal data systems, urging narrow permission grants, traffic inspection, and comprehensive access logging as mitigation measures.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in