Check Point Research uncovered a severe ChatGPT cross-account data leak that let attackers abuse a shared internal JFrog Artifactory service to move data between isolated user sessions. OpenAI confirmed the issue, decommissioned the vulnerable service, and patched the flaw after researchers demonstrated exposure of chat histories, private emails, and connected app data. #ChatGPT #OpenAI #JFrogArtifactory #CheckPointResearch
Keypoints
- Check Point Research found a cross-account data leak in ChatGPT.
- The flaw used a shared internal JFrog Artifactory service to bypass tenant isolation.
- Attackers could hide instructions in shared chats or custom GPTs.
- The exploit could expose chat histories, uploaded files, and connected Gmail or Microsoft 365 data.
- OpenAI decommissioned the vulnerable service and confirmed the fix.
Read More: https://securityonline.info/chatgpt-cross-account-data-leak/