ChatGPT processes a visible user request and a hidden task during the same turn, then returns the results through separate channels | Image: Check Point Research
At a Glance
| Category | Details |
|---|---|
| Organization | OpenAI (ChatGPT) |
| Data Exposed | Private user emails, chat histories, and connected app data |
| Records Affected | Unspecified (proof of concept demonstrated targeted extraction) |
| Cause | Shared internal JFrog Artifactory service lacking tenant isolation |
| Disclosure Status | Confirmed and patched by OpenAI |
| Source | Check Point Research |
Executive Summary
Check Point Research discovered a severe ChatGPT cross-account data leak that bypassed container isolation boundaries. Attackers exploited a shared internal software package service to establish a covert communication channel between distinct user accounts. By embedding malicious instructions in shared conversations or custom GPTs, attackers forced the AI to secretly extract private user data. OpenAI has since decommissioned the vulnerable internal service, neutralizing the threat.
What Was Exposed in the Leak
The ChatGPT cross-account data leak exposed highly sensitive personal and corporate information. The vulnerability allowed attackers to access any data reachable by the victim’s ChatGPT session. This included active chat histories and files uploaded directly to the conversation. More alarmingly, the flaw extended to connected third-party applications. If a user had linked their Google Drive, Microsoft Teams, or Gmail accounts, the attacker could secretly query those services. In their proof of concept, Check Point Research successfully commanded ChatGPT to retrieve private emails from a connected Gmail account and relay them back to the attacker’s server.
How the Vulnerability Operated
ChatGPT executes code within isolated containers to prevent unauthorized access. These containers cannot reach the public internet or communicate with each other directly. However, Check Point Research found that all containers shared access to an internal JFrog Artifactory instance used for retrieving software dependencies.
The researchers discovered that the Artifactory’s Item Management API permitted containers to read and write metadata properties. As the report explains, “The storage endpoint therefore turned the package service’s metadata into a shared clipboard between isolated containers.”
Attackers exploited this shared clipboard by embedding hidden instructions inside a shared chat link or a custom GPT. When the victim interacted with the chat, ChatGPT processed their visible request normally. Simultaneously, in the background, the AI executed the attacker’s hidden task. The report details, “ChatGPT processed the visible request and returned an ordinary answer. At the same time, it checked the hidden mailbox for a task from the attacker. If a task was waiting, ChatGPT carried it out using the tools and data available in the victim’s session, then returned the result back through the covert channel.” Because ChatGPT’s default settings allow “low-risk” read actions without user confirmation, the victim remained entirely unaware of the data theft.
Who Is Affected by This Incident
The vulnerability impacted ChatGPT users who interacted with untrusted shared conversations or third-party custom GPTs. Users with connected external applications, such as Gmail or Microsoft 365, faced the highest risk, as the AI could extract data from those linked services. While Check Point Research demonstrated the exploit successfully, there are no confirmed reports of malicious exploitation in the wild.
What Affected Users Should Do
Because OpenAI has already resolved the underlying infrastructure flaw, users do not need to take immediate technical action regarding this specific leak. However, this incident highlights the risks of granting AI assistants broad access to personal accounts. Users should navigate to their ChatGPT settings and review connected applications. For maximum security, users should change the default permission setting from “Allow low-risk actions” to “Always ask” to ensure the AI cannot read emails or documents without explicit approval.
The Company Response
Check Point Research disclosed their findings to OpenAI prior to publishing the report. According to the report, “We nevertheless disclosed our findings to OpenAI, who confirmed that the internal Artifactory instance identified during our research had been decommissioned.” By removing the shared service, OpenAI successfully dismantled the covert communication channel, securing the container isolation boundaries.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!