Check Point: Hidden ChatGPT Prompt Silently Leaked Gmail Data — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Check Point Research disclosed a proof-of-concept in which a single planted instruction in a ChatGPT conversation caused the chatbot to read a user's connected Gmail and forward the data to a second ChatGPT account through an internal channel — with only a delayed "Talked to Gmail" label revealing any read occurred.
- The attack could be seeded via three vectors: a pasted prompt, a shared ChatGPT conversation the user opens, or a custom GPT whose builder instructions are hidden from the user.
- The exfiltration channel abused ChatGPT's internal JFrog Artifactory instance, which fetches Python and npm packages for code-execution containers; its "properties" metadata feature acted as a shared clipboard between containers that were supposed to be isolated by account.
- No approval prompt fired because OpenAI's connected apps default to "Important actions" permission, which allows reads without asking — ChatGPT only prompts before actions that could "expose sensitive information" or "be hard to undo."
- This is the second covert channel Check Point has reported from the same ChatGPT subsystem — in March it disclosed a DNS-based exfiltration channel that OpenAI fixed on February 20.
- OpenAI confirmed the internal service behind the new channel was taken offline after disclosure; Check Point dated its work to June 2026 and did not say when the channel was closed.
Why it matters: Any ChatGPT user who connected Gmail, pasted third-party prompts, opened a shared chat, or used a custom GPT during the window the channel was live may have had mailbox contents silently read and forwarded — because the "Talked to Gmail" label appeared only after the read and connected apps default to a permission tier that skips approval for reads.
Ask SkimNews




