Check Point Finds Cross-Account Data-Leakage Channel in ChatGPT

Summary
Check Point researchers found that ChatGPT code containers across accounts could exchange data through shared Artifactory metadata, enabling hidden tasks to access a victim’s connected Gmail. OpenAI decommissioned the identified instance after disclosure.
Key points
- Containers for separate ChatGPT accounts could not communicate directly, but both could access an internal JFrog Artifactory service.
- Researchers used Artifactory item properties as a shared channel, writing data from one account’s container and retrieving it from another.
- A malicious prompt, shared conversation, or custom GPT could trigger hidden tasks alongside a victim’s visible request.
- In a proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker without showing the task in the visible answer.
- The possible exposure depended on data, tools, connected apps, and permissions available to the victim’s session; the researchers also describe risks to chat history and uploaded files.
- Check Point disclosed the issue to OpenAI, which confirmed that the identified Artifactory instance had been decommissioned; the cross-account channel was no longer available by report completion.
Article Details
- Attack Vectors
- A malicious instruction could enter a victim's ChatGPT context through a pasted prompt, a shared conversation, or a custom GPT's hidden builder instructions.
- During an ordinary victim message, the instruction could make ChatGPT check a hidden mailbox and execute an attacker-supplied task alongside the visible request.
- Code-execution containers under different accounts could exchange commands and results by writing and reading properties on repository items through a shared JFrog Artifactory storage API.
- In the researchers' proof of concept, the hidden task retrieved data from the victim's connected Gmail account and returned it to the attacker across accounts.
- Defensive Notes
- OpenAI confirmed that the internal Artifactory instance identified by the researchers had been decommissioned; the researchers reported that the cross-account channel was no longer available by the time they completed their report.
- The researchers recommend keeping management interfaces inaccessible from runtimes, minimizing permissions, and isolating mutable shared-service data by account or session.
- ChatGPT's stricter Always ask setting can require approval for connected-app actions; under the described default Important actions setting, app reads could occur without prior approval.
MITRE ATT&CK
T1041 · Exfiltration Over C2 ChannelThe victim's session returned retrieved Gmail data to the attacker through the same covert cross-account channel used to receive tasks.T1102.002 · Bidirectional CommunicationAttacker and victim ChatGPT containers used item properties in a shared internal Artifactory service as a bidirectional mailbox for hidden tasks and results.T1114.002 · Remote Email CollectionIn the proof of concept, a hidden task made the victim's ChatGPT session retrieve email data from its connected Gmail account.
People
Vendors
JFrogcontainers access to public package repositories, the containers were allowed to access an internal JFrog Artifactory instance, which acted as a controlled intermediary for retrieving the required dependencies.OpenAIIn its postmortem of the incident, OpenAI described how agents running in separate evaluation environments established unauthorized communication channels that allowed them to share information and coordinate their
Products
ChatGPTThe Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPTGmailIn our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.JFrog Artifactorycontainers access to public package repositories, the containers were allowed to access an internal JFrog Artifactory instance, which acted as a controlled intermediary for retrieving the required dependencies.