started · updated
ChatGPT security flaw allowed data extraction between accounts
Check Point Research has identified a security flaw in ChatGPT that allowed a hidden channel to bypass user isolation. The vulnerability enabled an attacker to send commands to a victim's session via an internal service, potentially allowing the extraction of sensitive data from connected accounts, such as Gmail.
The flaw functioned through an internal package distribution service that all ChatGPT code execution containers could access. While these containers were intended to be isolated, the service allowed them to read and write shared data across different accounts. In a demonstration, an attacker was able to extract data from a victim's linked Gmail account without the user noticing any anomaly in their conversation.
To trigger the attack, a victim would need to interact with a malicious prompt, a shared conversation link, or a custom GPT. The extent of the data accessible depended on the specific applications and permissions already granted to the user's session.
OpenAI has confirmed that the issue is no longer exploitable, as the internal instance of JFrog Artifactory involved in the process has been decommissioned.