Check Point Research reported that a single hidden instruction in a ChatGPT conversation could make ChatGPT silently exfiltrate data from a user’s connected Gmail and conversation context while still replying normally. The researchers said the issue used a hidden communication channel between ChatGPT containers via internal JFrog Artifactory metadata, and that OpenAI has since taken the internal service offline. #CheckPointResearch #ChatGPT #Gmail #JFrogArtifactory #OpenAI
Keypoints
- A hidden prompt could make ChatGPT work for an attacker without the user noticing.
- The proof of concept showed data being read from a connected Gmail account and sent to another ChatGPT account.
- The same method could also copy chat history and files from the conversation.
- The attack could be planted through pasted prompts, shared conversations, or custom GPT builder instructions.
- Check Point found an internal JFrog Artifactory channel that let separate ChatGPT containers exchange data.
Read More: https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html