Planted prompt turned ChatGPT into a hidden Gmail relay

Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.

CSBadmin
2 Min Read

A ChatGPT conversation can be weaponized to drain a connected Gmail account while the user gets perfectly normal answers. Check Point Research built the attack around a single planted instruction and demonstrated the stolen mail traveling to a second ChatGPT account through a hidden channel.

The covert path exploits ChatGPT’s package-fetching setup. Containers that run code for separate conversations are isolated from each other and the open internet, but all share one internal JFrog Artifactory instance. Read access to that service was enough to write named properties on cached files and read them back, and those properties crossed account boundaries: a value planted from one container surfaced in a different account’s session, effectively a shared clipboard.

Delivery of the malicious instruction needs one of three openings: a user-pasted prompt, an opened shared conversation, or a custom GPT with the payload baked into its hidden builder instructions. One ordinary message then sets the relay in motion. Users see a small “Talked to Gmail” label only after the read already happened, since connected apps default to permission settings that skip prompts.

OpenAI took the reported channel offline after Check Point’s disclosure, so there is no client update to install. The finding follows a DNS-based leak path from the same ChatGPT component that OpenAI closed in February, and it is the second time a shared internal service turned into an unintended bridge between supposedly isolated environments.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.