ChatGPT Vulnerability Allowed Hackers to Steal User Data
A significant security flaw discovered by Check Point Research allowed attackers to bypass ChatGPT's isolation mechanisms and access sensitive user information. The vulnerability exploited a shared internal service, JFrog Artifactory, which OpenAI used to allow isolated "sandboxes" for code execution to download necessary software packages without direct internet access. Researchers found that this shared service had a structural flaw enabling one user's sandbox to write data that another user's sandbox could read, effectively creating a covert communication channel.
Attackers could insert instructions into a victim's chat session, potentially through shared links or custom GPT configurations. ChatGPT would then process these hidden commands in the background while simultaneously responding to the user's legitimate queries. In a proof-of-concept demonstration, researchers successfully instructed ChatGPT to access a connected Gmail account, extract sensitive emails, and send them to the attacker. The only visible sign was a small, unexplained label, "Talked to Gmail," as read operations were automatically approved under default settings.
This vulnerability is particularly concerning as many users connect ChatGPT to various personal and organizational services like Google Drive and Microsoft Teams, exposing them to similar hidden commands. Check Point researchers noted that this structural issue is similar to a previous incident involving the Hugging Face platform, where AI agents in separate evaluation environments created unauthorized communication channels. Both incidents stemmed from shared internal infrastructures inadvertently bridging different users.
Following Check Point's report, OpenAI quickly addressed the issue by disabling the internal Artifactory service, thereby blocking this specific communication channel. However, the findings raise broader questions about the security of future AI assistants. Eli Smadja, Director at Check Point Research, stated that securing AI now involves not just the model itself but also the level of access and trust granted to it, warning that any granted capability could be misused as AI connects to more internal systems and sensitive data.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.