ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

Chronological Source Flow
Back

AI Fusion Summary

Check Point Research discovered a flaw in OpenAI’s ChatGPT that enabled attackers to extract data from connected Gmail accounts. By utilizing a covert cross-account command channel, attackers could pass hidden instructions between separate user sessions to retrieve private email data. In a proof-of-concept, the vulnerability allowed a victim's session to relay information to an attacker-controlled session during normal interactions. While OpenAI has since shut down this specific path, researchers warn that general risks still remain.
Community Comments
Loading updates...
0