started · updated
ChatGPT vulnerability allows covert Gmail data leakage
Researchers at Check Point Research have identified a security vulnerability in ChatGPT that allows for covert cross-account data leakage. Through a technique described as a ‘planted-prompt attack,’ an attacker can embed hidden instructions within a conversation or a custom GPT.
These instructions trigger a secondary, invisible workflow that operates in the background while the user receives a standard, seemingly normal response. In a proof of concept, researchers demonstrated that this method could be used to access data from a victim’s connected Gmail account and relay that information to an attacker’s ChatGPT account via an internal service used for software package delivery.
The extent of the potential data theft depends on the specific permissions and connected apps available to the user's session, including conversation history and uploaded files. OpenAI has reportedly taken the internal service element that enabled this channel offline.