Check Point Finds ChatGPT Flaw That Leaked Gmail Data Across User Accounts
Security researchers at Check Point discovered a vulnerability in ChatGPT's code execution environment that allowed attackers to covertly access Gmail data belonging to other users. The flaw stemmed from a shared internal service based on JFrog's Artifactory, which inadvertently acted as a common channel between containers that should have been fully isolated. Attackers could embed hidden instructions in shared metadata, causing a victim's ChatGPT session to silently fetch and transmit connected account data — including Gmail, Google Drive, and GitHub — without any visible warning to the user. OpenAI has since patched the vulnerability and shut down the related service, though analysts note the incident exposes a broader risk pattern for any organization integrating AI tools with internal data. Security experts recommend granting minimal permissions to AI integrations, enforcing detailed access logging, and routing connected-app traffic through data-monitoring systems to detect similar covert leaks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in