New Findings Expose Cross-Session Vulnerabilities in ChatGPT That Compromise User Data

Sep 09, 2026 658 views

A recent investigation by Check Point highlights a serious security vulnerability within OpenAI's ChatGPT, which enabled malicious actors to siphon data from victims' connected Gmail accounts by leveraging a hidden communication channel between user sessions. This finding raises significant concerns about the security assumptions surrounding AI applications.

In a proof-of-concept demonstration, Check Point illustrated how an attacker could exploit a victim’s ChatGPT session to retrieve email information and transmit it back to the attacker’s own session during a regular interaction. According to Check Point researcher Alexey Bukhteyev, the exploit revolves around a covert method where the AI system, though not directly compromised, is manipulated to perform unintended actions within its operational parameters.

OpenAI acknowledged the issue and stated that the vulnerability has been resolved, confirming the decommissioning of the internal service that facilitated these exploits.

A Covert Cross-Account Channel

The core of this vulnerability lies within ChatGPT's coding environment, which operates via isolated containers designated for individual user accounts. To enable software installations within these containers, OpenAI routes requests through an internal service based on JFrog Artifactory. While these containers are designed to be independent and secure, Check Point discovered they could still access a shared pool of metadata. This effectively turned the package delivery metadata into a type of “shared clipboard,” contradicting the intended isolation between user sessions.

This oversight in isolation is alarming. In a sector where data security is often touted as a top priority, such weaknesses remind us that all systems are vulnerable. The report indicated that by inputting crafted instructions into this metadata, attackers could direct tasks to compromise a victim's session without their knowledge. Given the intricate nature of modern software systems, the idea that a seemingly isolated environment can be infiltrated so easily should be troubling for users and IT departments alike.

Unauthorized Gmail Data Access

During their testing, Check Point demonstrated that these hidden tasks could instruct ChatGPT to extract data from a connected Gmail account and relay it back to the attacker. This situation reflects a broader trend in cybersecurity; where interfaces and reported security measures can appear intact, yet dangerous vulnerabilities linger in the background. While the user interface remained unaltered and appeared normal to the user, it masked the nefarious background operation where private information was being accessed.

The potential for abuse was broad, as the attack was capable of accessing not just email, but also files across connected applications like Google Drive, Microsoft Teams, and GitHub. It's unsettling to think about the wealth of information that could be harvested without user awareness. The only indication of a breach was a minor label showing that Gmail had been accessed after the fact— a disconcerting realization for users who may never have suspected that their data was jeopardized.

Link to Infrastructure Issues

Check Point's findings also connect to previously disclosed weaknesses involving the same JFrog Artifactory infrastructure. Notably, a separate breach involving Hugging Face demonstrated that various vulnerabilities could arise from shared internal services, necessitating a reevaluation of risk management strategies among enterprises that utilize AI tools. If you're working in this space, it's essential to take such incidents seriously; they illuminate not only the flaws of specific systems but represent a larger vulnerability across interconnected platforms.

Shilpi Handa, associate research director at IDC, emphasized that organizations should question AI vendors about the capabilities of their containers and data isolation measures. This is more significant than it looks; CIOs must probe whether one container can access data from another and assess the extent of any isolation failures experienced in their operational environments.

Immediate Controls for Enterprises

To mitigate exposure, Handa advised enterprises to implement stricter authorization protocols for connected applications, limiting access to only what's necessary. For instance, it's recommended to permit calendar integrations without automatically allowing access to Gmail and Drive. This kind of granular control can significantly reduce an organization's risk profile. Implementing strict permission models can help create an environment where the fallout from a breach is minimized.

Furthermore, organizations should consider routing data traffic through Data Loss Prevention (DLP) tools or Cloud Access Security Brokers (CASBs) to monitor sensitive information before it exits the system. Without rigorous data monitoring, organizations are becoming targets for breach events that can have lasting reputational and financial damage. Implementing logging for connected app interactions that records timestamps and data categories is crucial; without this, detecting breaches similar to the one discovered becomes nearly impossible. It's all too easy for malicious actors to exploit unsuspecting platforms when organizations lack visibility into their application ecosystems.

Finally, some vendor consoles offer options to configure how certain high-risk applications, such as Gmail or Drive, handle data. This involves requiring explicit approval for access rather than permitting automatic interaction, which could invariably bolster security for sensitive data domains like legal and financial records. And this is the part most people overlook: taking small, proactive steps in configuring applications can save companies from larger financial and reputational harms later on.

Implications and Future Outlook

This incident serves as a wake-up call across the tech industry and highlights the pressing need for stronger security protocols in AI applications. As AI integration becomes more widespread, the implications for data privacy and security could deepen. Companies may need to rethink their architecture and operational practices, ensuring that security is not just an afterthought but an intrinsic part of system design.

With the rapid pace of AI development, users must remain vigilant. Keeping abreast of emerging vulnerabilities and maintaining an open dialogue with service providers will be essential. As this situation continues to evolve, organizations must prioritize security audits and implement stringent data management policies. The landscape of application security is shifting, and those that adapt will likely outpace competitors who fail to acknowledge these critical vulnerabilities.

Source: David Brown · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

ChatGPT flaw lets attackers pull Gmail data across accoun...