Check Point Discovers Cross-Account ChatGPT Flaw Enabling Covert Gmail Data Theft; OpenAI Decommissions Artifactory Channel
Check Point Research found that ChatGPT's code-execution containers could reach a shared internal JFrog Artifactory service, creating a covert cross-account channel that prompt injection could abuse to silently exfiltrate Gmail and other connected-app data;…
Check Point Research disclosed a covert cross-account command channel in ChatGPT's code execution environment. Containers meant to be isolated could access a shared internal service based on JFrog Artifactory, whose item metadata API enabled a bidirectional cross-tenant channel between ChatGPT accounts. Attackers could embed hidden prompt-injection instructions in shared conversations or custom GPT configurations, causing a victim's session to silently retrieve connected Gmail email data and relay it to an attacker-controlled account during an ordinary-looking interaction. In a proof of concept, the only visible hint of the exfiltration was a post-hoc 'Talked to Gmail' activity label. The attack scope extended to any connected apps the session was authorized for, including Google Drive, Microsoft Teams, and GitHub. OpenAI fixed the issue and decommissioned the internal Artifactory instance by publication time, closing the covert channel. Per CSO Online, the same shared infrastructure was also involved in the separately disclosed Hugging Face compromise, though via different techniques. Security experts cited recommend narrow app grants, DLP/CASB inspection, and SIEM logging of connected-app reads as mitigations.
- Discovered by Check Point Research; reported 2026-09-09.
- ChatGPT sandbox/code-execution containers, meant to be isolated, could access a shared internal JFrog Artifactory service.
- The Artifactory item metadata API enabled a bidirectional cross-tenant covert channel between ChatGPT accounts.
- Attack vector: hidden prompt-injection instructions embedded in shared conversations or custom GPT configurations.
- Proof of concept exfiltrated connected Gmail data to an attacker-controlled session; the only visible trace was a 'Talked to Gmail' activity label.
- Attack scope covered any connected apps the session was authorized for, including Google Drive, Microsoft Teams, and GitHub.
- OpenAI patched the issue and decommissioned the internal Artifactory service, eliminating the channel by publication time.
- The same shared infrastructure was also tied to the separately disclosed Hugging Face compromise, though via different techniques (per CSO Online).
Coverage timelineoldest first · each row is one article
- · 7d agoChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
GBHackers· 62
Check Point found a patched ChatGPT flaw where prompt injection and a shared Artifactory service let attackers covertly exfiltrate Gmail data across accounts.