importantSYS.SOURCE: The Hacker News• 2026-09-08T19:49:17+05:30
ChatGPT Vulnerability Exploits Hidden Prompt to Exfiltrate Gmail Data
A vulnerability in ChatGPT allowed attackers to secretly exfiltrate Gmail data through a hidden channel by planting a malicious prompt in conversations. Check Point Research disclosed the issue to OpenAI, which addressed the internal service but no user action was required.
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual.
In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
*** END OF TRANSMISSION ***