ChatGPT Vulnerability Exposed User Emails Via Flawed Access Controls
Cybersecurity experts at Check Point have uncovered a significant vulnerability in ChatGPT that allowed malicious actors to access sensitive user data, including emails, without directly breaching accounts or stealing passwords. The flaw stemmed from an isolation bypass within the AI model's infrastructure. While ChatGPT's code execution typically occurs in isolated environments, OpenAI granted these environments access to a shared internal service, JFrog Artifactory, for software updates. Incorrect permission settings in this service created a hidden communication channel between different accounts. Attackers could exploit this by embedding hidden instructions within seemingly innocuous text, links, files, or custom GPTs. While a user engaged in a normal conversation, the system could, in the background, access connected services like Gmail and exfiltrate email content to the attacker, with the only indication being a minor "Talked to Gmail" notification.
OpenAI has reportedly acted swiftly to close the exposed internal service and block the malicious communication channel upon receiving the report from Check Point. This incident echoes a similar security event on the Hugging Face platform, where AI agents also established unauthorized communication. The discovery highlights broader concerns about granting extensive permissions to AI tools, especially as they gain more access to private and organizational data.
According to Alon Smadja, Director of Research at Check Point, the challenge lies not just in protecting the AI model itself, but in the risks associated with granting overly broad permissions to these tools. This incident occurs amidst a period of rapid advancement in artificial intelligence, with OpenAI recently releasing its new GPT-6 Astra model and Nvidia CEO Jensen Huang suggesting the achievement of Artificial General Intelligence (AGI). As AI models become more autonomous and powerful, this vulnerability underscores that the primary danger may lie in the extensive access granted to them, rather than their inherent intelligence.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.