Check Point: Planted ChatGPT Prompts Stole Gmail Data — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Check Point Research published a proof-of-concept showing that one instruction hidden in a ChatGPT conversation read data from a connected Gmail account and passed it to a second ChatGPT account through a hidden channel, while the visible reply said nothing about it.
- The hidden channel exploited an internal JFrog Artifactory instance that ChatGPT uses to fetch Python and npm packages — containers from separate conversations, including under different accounts, could attach named metadata properties to a shared cached file and read them back, turning package-service metadata into a cross-account notepad.
- Three delivery vectors made the attack viable: a prompt the user pastes in, a shared ChatGPT conversation the user opens, or a custom GPT whose unseen builder instructions carry the payload.
- In ChatGPT's Thinking mode, the planted instruction split one turn into two parallel work streams — one answering the user, one carrying out an attacker task checked against a hidden mailbox — with the only visible sign being a post-hoc "Talked to Gmail" label that offered no allow or refuse option.
- OpenAI's connected-app defaults list "Important actions" as the default permission, letting ChatGPT read from apps like Gmail without prompting; users can switch to "Always ask," while Enterprise and Edu workspaces ship with apps off by default and Business plans with them on.
- This is Check Point's second channel out of the same part of ChatGPT — the first, reported in March, used DNS lookups to send conversation data to an external server, and OpenAI patched it on February 20.
- Check Point disclosed the finding to OpenAI, which confirmed the internal service behind the channel had been taken offline; no user update is required, and Check Point dated its work to June 2026 without specifying when the channel stopped working.
Why it matters: The flaw converted a package-management convenience into a covert cross-account communication channel, and it underscores that ChatGPT's connected-app defaults let one turn read Gmail without a user prompt. Anyone who linked Gmail to ChatGPT during the window the channel was open could have had inbox data silently read by anyone who got them to paste or open a malicious prompt.
Ask SkimNews




