cd /news/ai-safety/chatgpt-could-secretly-steal-gmail-d… · home topics ai-safety article
[ARTICLE · art-124379] src=itdaily.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

ChatGPT could secretly steal Gmail data via shared links

Check Point Research has discovered a security flaw in ChatGPT that could allow attackers to secretly exfiltrate Gmail data via manipulated prompts, shared links, or custom GPTs, abusing the user's legitimate permissions. OpenAI has patched the specific vulnerability, but Check Point warns that similar techniques could affect other AI applications like Microsoft Copilot, and advises organizations to inventory AI applications and conduct proactive security testing.

by read2 min views2 publishedSep 9, 2026
ChatGPT could secretly steal Gmail data via shared links
Image: Itdaily (auto-discovered)

Check Point has discovered a security flaw between ChatGPT and Gmail. An attacker could secretly exfiltrate emails via a hidden communication channel.

Security firm Check Point warns of a vulnerability involving ChatGPT. The popular chatbot could potentially grant attackers access to your confidential emails in Gmail. OpenAI has since resolved the vulnerability, but experts warn of similar risks in other AI applications.

The security flaw demonstrates how vulnerable integrated AI systems are when users grant them extensive access to external services. In the proven attack scenario, a manipulated prompt, a shared web link, or a custom GPT was sufficient to take control of a victim’s account. ChatGPT then retrieved data from Gmail using the owner’s legitimate permissions and forwarded it to the attacker, while the chat window remained perfectly normal for the victim.

Abuse of trust #

Check Point Research refers to this phenomenon as a ‘manipulated insider.’ It involves an AI assistant that is manipulated via legitimate access rights to act on behalf of an attacker within an organization’s trust framework. No stolen passwords or malware are involved; only the permissions entrusted to the assistant by the user themselves are abused. OpenAI has since patched the specific leak, but the underlying technique remains a point of concern.

According to Fred Streefland, CISO at Check Point, this is not an isolated ChatGPT problem. Attackers can apply similar techniques to existing capabilities and vulnerabilities in other AI applications, such as Microsoft Copilot. He believes the infrastructure behind modern AI is so complex that security flaws remain inevitable. The warning states that when a system is smart, it is simultaneously vulnerable.

Lack of oversight #

According to Streefland, the lack of oversight is the biggest pitfall for companies. As a result, the identification and protection domains within cybersecurity policies must scale up rapidly. After all, those who lack visibility into their systems cannot adequately secure them.

Check Point advises security managers to create an inventory of all AI applications and active AI agents within the organization. Additionally, the security firm advocates for proactive testing of integrations through specialized red teaming and vulnerability assessments before they go operational. Only through strict governance, continuous monitoring, and a preventive approach will AI remain a valuable tool rather than a digital security risk.

── more in #ai-safety 4 stories · sorted by recency
── more on @check point research 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/chatgpt-could-secret…] indexed:0 read:2min 2026-09-09 ·