Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Erik and Lyle Menendez eligible to face parole board early next year | Los Angeles

    September 8, 2026

    Ursula von der Leyen condemns ‘shocking’ Ratko Mladić funeral in Serbia – POLITICO

    September 8, 2026

    Tim Montgomerie quits Reform following suspension

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Erik and Lyle Menendez eligible to face parole board early next year | Los Angeles
    • Ursula von der Leyen condemns ‘shocking’ Ratko Mladić funeral in Serbia – POLITICO
    • Tim Montgomerie quits Reform following suspension
    • Far-right port protests: police told to improve intelligence gathering | Police
    • Apple and Google Miss Deadline to Block Child Nudity on Their Phones in the UK
    • NVIDIA Announces CUDA Rust with cuda-oxide (SIMT) and cutile-rs (Tile) for Compile-Time-Safe GPU Kernels
    • ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account
    • Robinhood Takes Stakes in Crypto.com, OG.com
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user’s question as usual.

    In the company’s proof of concept, that hidden work read data from the user’s connected Gmail account and passed it to a second ChatGPT account through a hidden channel between the two. The reply the user saw said nothing about it.

    Check Point said the same channel could also copy out the chat history and the files in that conversation.

    How much an attacker could take depended on what the session could already access, including its data, tools, other connected apps, and permissions.

    The instruction had to be in the conversation before any of this worked. Check Point named three ways to get it there: a prompt the user pastes in, a shared ChatGPT conversation the user opens, or a custom GPT that holds it in its builder instructions, which are not shown to the user.

    After that, one ordinary message was enough to start it. Check Point wrote the instruction so that ChatGPT, in Thinking mode, ran two streams of work in the same turn.

    Cybersecurity

    ChatGPT answered the user. At the same time, it checked a hidden mailbox for a task from the attacker, carried out that task using the tools in the user’s session, and sent the result back. The instruction told the model to keep the two streams separate, so the hidden task never appeared in the visible answer.

    The only sign that an app had been used was a small “Talked to Gmail” label above the answer. It recorded a read that had already happened and gave the user no chance to allow or refuse it.

    Nothing asked the user first because of how connected apps work by default. OpenAI’s documentation lists Important actions as the default permission, which allows ChatGPT to read from an app without prompting. ChatGPT asks only before actions that could have a real effect outside ChatGPT, expose sensitive information, or be hard to undo.

    A user who wants to be asked every time can switch to Always ask. In Business, Enterprise, and Edu workspaces, admins choose which actions each app may take and who may use it. Apps are on by default on Business plans and off by default on Enterprise and Edu.

    Check Point said it disclosed the finding to OpenAI and that OpenAI confirmed the internal service behind the channel had been taken offline. There is no update for users to install.

    The channel ran between the containers where ChatGPT runs code. ChatGPT builds one for each conversation when a task calls for it.

    OpenAI’s documentation says the Python environment ChatGPT uses for data analysis cannot make requests to the web or to outside APIs. Check Point said containers built for separate conversations, including ones under different accounts, had no direct path to each other either.

    All of them could reach one internal service. ChatGPT sometimes needs to install extra Python or npm packages. Rather than allowing the containers to reach public package repositories, each was allowed to talk to an internal JFrog Artifactory instance that fetched packages for it.

    That instance let a container attach named values, called properties, to a stored file and read them back. The credentials the container held for read access were also enough to write those properties. They sat in environment variables, where code that ChatGPT ran could pick them up. The code did not need to steal a separate secret or escalate privileges.

    The properties were not kept separate by account. From a container under one account, Check Point attached a property named chatgpt_test_ts, containing the current time, to a cached file. In a conversation under a different account, it requested that file’s properties and received the same name and value.

    Cybersecurity

    A property can carry plain text or Base64, and anything too large for one can be split across several and reassembled at the other end. That turned the package service’s metadata into a shared clipboard between containers that were not supposed to reach each other.

    This is the second channel out of the same part of ChatGPT that Check Point has reported. In March, it described one that used DNS lookups to send conversation data to an external server, and said OpenAI fixed it on February 20.

    The case is separate from the Hugging Face incident, in which OpenAI’s own models turned an internal Artifactory instance into a message board during the company’s security tests.

    Check Point said the mechanism it found was different and described both as cases in which “a shared internal service became an unintended communication layer” across environments meant to stay isolated.

    Check Point dated its work to June 2026 and did not say when the channel stopped working, so the report does not show how long it was open.

    account ChatGPT data Flaw Gmail planted Prompt Send Victims
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft releases Windows 10 KB5122878 extended security update

    Windows 11 cumulative updates KB5124008 & KB5122880 released

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

    Adobe fixes critical Magento zero-day exploited to backdoor servers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Erik and Lyle Menendez eligible to face parole board early next year | Los Angeles

    September 8, 2026

    Ursula von der Leyen condemns ‘shocking’ Ratko Mladić funeral in Serbia – POLITICO

    September 8, 2026

    Tim Montgomerie quits Reform following suspension

    September 8, 2026

    Far-right port protests: police told to improve intelligence gathering | Police

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Erik and Lyle Menendez eligible to face parole board early next year | Los Angeles

    September 8, 2026

    Ursula von der Leyen condemns ‘shocking’ Ratko Mladić funeral in Serbia – POLITICO

    September 8, 2026

    Tim Montgomerie quits Reform following suspension

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.