Check Point Finds Cross-Account Data-Leakage Channel in ChatGPT

· Original article ↗

Summary

Check Point researchers found that ChatGPT code containers across accounts could exchange data through shared Artifactory metadata, enabling hidden tasks to access a victim’s connected Gmail. OpenAI decommissioned the identified instance after disclosure.

Key points

  • Containers for separate ChatGPT accounts could not communicate directly, but both could access an internal JFrog Artifactory service.
  • Researchers used Artifactory item properties as a shared channel, writing data from one account’s container and retrieving it from another.
  • A malicious prompt, shared conversation, or custom GPT could trigger hidden tasks alongside a victim’s visible request.
  • In a proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker without showing the task in the visible answer.
  • The possible exposure depended on data, tools, connected apps, and permissions available to the victim’s session; the researchers also describe risks to chat history and uploaded files.
  • Check Point disclosed the issue to OpenAI, which confirmed that the identified Artifactory instance had been decommissioned; the cross-account channel was no longer available by report completion.

Article Details

Attack Vectors
  • A malicious instruction could enter a victim's ChatGPT context through a pasted prompt, a shared conversation, or a custom GPT's hidden builder instructions.
  • During an ordinary victim message, the instruction could make ChatGPT check a hidden mailbox and execute an attacker-supplied task alongside the visible request.
  • Code-execution containers under different accounts could exchange commands and results by writing and reading properties on repository items through a shared JFrog Artifactory storage API.
  • In the researchers' proof of concept, the hidden task retrieved data from the victim's connected Gmail account and returned it to the attacker across accounts.
Defensive Notes
  • OpenAI confirmed that the internal Artifactory instance identified by the researchers had been decommissioned; the researchers reported that the cross-account channel was no longer available by the time they completed their report.
  • The researchers recommend keeping management interfaces inaccessible from runtimes, minimizing permissions, and isolating mutable shared-service data by account or session.
  • ChatGPT's stricter Always ask setting can require approval for connected-app actions; under the described default Important actions setting, app reads could occur without prior approval.

MITRE ATT&CK

People

Vendors

Products

Related Articles