{"slug": "chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel", "title": "ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel", "summary": "Check Point Research disclosed a flaw in OpenAI's ChatGPT that allowed attackers to extract data from a victim's connected Gmail account via a hidden cross-account command channel, which OpenAI has since fixed. The proof-of-concept exploited shared metadata in an internal service based on JFrog Artifactory to relay instructions between isolated containers, potentially accessing Gmail, Google Drive, Microsoft Teams, and GitHub connectors. Check Point researcher Alexey Bukhteyev noted the attack was a 'coerced insider' scenario, and IDC's Shilpi Handa advised CIOs to question AI vendors about isolation failures.", "body_md": "A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point.\n\nIn a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT session could retrieve email data and relay it to an attacker-controlled session within a single, seemingly normal interaction.\n\n“Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session,” Check Point researcher Alexey Bukhteyev [wrote](https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/) in the report. “In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.”  \n\nOpenAI has since fixed the issue, according to the report, confirming that the internal service involved has been decommissioned.\n\nCheck Point described this as a “coerced insider” scenario, where the AI system itself is not compromised but can be manipulated into performing unintended actions within the organization’s trust boundary.\n\nThe attack’s reach extended to anything the victim’s session was already authorized to access, including Google Drive, Microsoft Teams and GitHub connectors, not just Gmail, the report added.\n\nThe vulnerability stemmed from ChatGPT’s code execution environment, where tasks run inside isolated containers tied to individual user accounts.\n\nTo support software installation inside those containers, OpenAI routes package requests through an internal service based on JFrog Artifactory, according to the report.\n\nWhile containers are not supposed to communicate with each other, Check Point found that each container could write and read metadata in that shared service.\n\n“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another,” the report said.\n\nBy writing instructions into that shared metadata, an attacker’s session could pass tasks to a victim’s session. “A crafted instruction could make a victim’s ChatGPT session quietly process a second stream of tasks alongside the conversation the victim could actually see,” Check Point said in the report.\n\nIn its demonstration, Check Point showed that the hidden task could instruct ChatGPT to retrieve data from a victim’s connected Gmail account and return it to the attacker.\n\n“The visible answer looked completely ordinary,” the report said, even as the hidden task executed in parallel.\n\nThe scope of the attack depended on what the victim’s session was authorized to access, including email, files, and other connected applications such as cloud storage or collaboration tools, according to Check Point.\n\nUser awareness was minimal. The only indication observed was a small label ‘Talked to Gmail’ showing that an external service had been accessed, logged after the action had already taken place, the report said.\n\nCheck Point Research said its proof of concept was already working before a separate chain of activity on the same Artifactory instance led into the Hugging Face compromise that OpenAI has since disclosed publicly. The two incidents used different techniques but trace back to the same shared internal service.\n\nShilpi Handa, associate research director at IDC, said a repeat isolation failure on the same infrastructure changes how enterprises should weigh vendor risk.\n\n“Can one tenant’s container read or write data another tenant’s container can also access?” is a question CIOs should be putting directly to AI vendors, Handa said, since the answer isn’t something customers can verify independently.\n\nHanda said enterprises should also ask vendors how many isolation-boundary findings they have logged over the past 12 months and what changed structurally after each one.\n\nOpenAI did not immediately respond to a request for comment.\n\nHanda said enterprises don’t need to wait on vendor answers to reduce exposure. She recommended authorizing connected apps narrowly rather than by default, granting a calendar connector without also enabling Gmail and Drive access.\n\nA limited grant “narrows what any container-level leak can expose,” Handa said.\n\nShe also recommended routing connected-app traffic through DLP or CASB inspection to catch regulated data before it leaves the pipeline, and requiring an API or webhook that logs every connected-app read and write, with timestamp and data category, exported to the enterprise’s own SIEM.\n\nWithout that logging, Handa said, “you can’t detect this class of leak even post-patch.” She said admin consoles at some vendors let customers override default risk-tiering on reads involving Gmail or Drive, forcing explicit approval rather than automatic access. That override is worth applying specifically to confidential or regulated data sources such as legal, HR, or finance systems, she said.", "url": "https://wpnews.pro/news/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel", "canonical_source": "https://www.csoonline.com/article/4220203/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html", "published_at": "2026-09-09 11:48:19+00:00", "updated_at": "2026-09-09 12:47:26.108979+00:00", "lang": "en", "topics": ["ai-safety", "ai-products", "ai-infrastructure"], "entities": ["OpenAI", "ChatGPT", "Check Point Research", "Alexey Bukhteyev", "JFrog Artifactory", "Gmail", "Google Drive", "Microsoft Teams"], "alternates": {"html": "https://wpnews.pro/news/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel", "markdown": "https://wpnews.pro/news/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.md", "text": "https://wpnews.pro/news/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.txt", "jsonld": "https://wpnews.pro/news/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.jsonld"}}