ChatGPT Vulnerability Enables Gmail Data Exfiltration via Malicious Prompts

ChatGPT Vulnerability Enables Gmail Data Exfiltration via Malicious Prompts

First seen 8 Sep 2026, 15:46 UTC Research.CheckpointThehackernews 63.0

Article Content

Browse articles
ThreatCluster

Check Point Research revealed a vulnerability in ChatGPT that allows attackers to exfiltrate data from a victim's Gmail account through a hidden command channel. By planting a specific instruction in a ChatGPT conversation, an attacker can have ChatGPT perform tasks on behalf of the victim while providing normal responses to their queries. The attack method relies on the victim's session permissions and connected apps, allowing the attacker to access sensitive information, including chat history and files. The covert channel operates between isolated containers used by ChatGPT, which normally cannot communicate with each other or the public Internet. Check Point disclosed the issue to OpenAI, which has since confirmed that the internal service facilitating this vulnerability has been taken offline, although no updates for users have been released. The attack's effectiveness depends on the permissions granted to the ChatGPT session, with the default setting allowing data access without user prompts. This incident highlights the evolving security challenges associated with AI systems that can execute code and access user data.

Key Points: • Attackers can exfiltrate Gmail data via hidden commands in ChatGPT. • The vulnerability allows attackers to operate without user awareness. • OpenAI confirmed the internal service facilitating the exploit has been disabled.

Ask AI about this cluster

Timeline

2026-09-08
Check Point Research reveals ChatGPT vulnerability
A report details how attackers can exfiltrate Gmail data through malicious prompts in ChatGPT conversations.
Research.Checkpoint
2026-09-08
OpenAI confirms service taken offline
Following the disclosure, OpenAI confirmed that the internal service enabling the data exfiltration has been disabled.
Thehackernews