ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
AI Summary
Check Point Research discovered a vulnerability in ChatGPT that allowed a maliciously crafted prompt to enable covert data exfiltration from a user's session. By exploiting a shared internal JFrog Artifactory service used for package caching, an attacker could establish a hidden communication channel between isolated ChatGPT containers across different accounts. This allowed the silent reading of Gmail data, chat history, and files from a victim's session and transmitting them to an attacker-controlled account without user consent or awareness. The vulnerability stemmed from improper isolation in the internal service and excessive container permissions, which allowed write access to shared metadata properties. OpenAI confirmed the issue and took the internal service offline, but no user-facing patch was required or released.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | chatgpt_test_ts | Details → |