< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-08T19:49:17+05:30

ChatGPT Vulnerability Exploits Planted Prompt to Exfiltrate Gmail Data

A vulnerability in ChatGPT allowed a planted prompt to secretly exfiltrate a user's Gmail data to an attacker-controlled account through an internal service. The exploit leveraged shared metadata properties in ChatGPT's container environment to bypass isolation mechanisms.

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual.

In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

Read original article

*** END OF TRANSMISSION ***