OpenAI patches ChatGPT data exfiltration flaw

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Check Point discovered a ChatGPT vulnerability that silently exfiltrated user messages, uploaded files, and sensitive content through a hidden DNS-based "covert transport mechanism" in the Linux runtime, bypassing all AI guardrails with no user warnings or approval dialogs
- OpenAI patched the flaw on February 20, 2026, after responsible disclosure; there is no evidence the issue was ever exploited maliciously
- The same hidden DNS path could be weaponized to establish remote shell access and achieve command execution inside ChatGPT's code-execution environment
- Attackers could deliver the exploit by tricking users into pasting a malicious prompt (e.g., offering "premium features for free") or by baking the logic directly into custom GPTs, magnifying the threat surface
- BeyondTrust separately found a critical command injection flaw in OpenAI Codex that stole GitHub User Access Tokens by smuggling arbitrary commands through the GitHub branch name parameter in task creation requests
- The Codex vulnerability, patched February 5, 2026 after being reported December 16, 2025, granted attackers lateral movement and read/write access to victims' entire codebases
- Check Point's Eli Smadja warned that "native security controls are no longer sufficient on their own" as AI platforms evolve into "full computing environments handling our most sensitive data"
Why it matters: For enterprises embedding ChatGPT and Codex in workflows with proprietary code and confidential data, these twin disclosures show that AI agent execution environments — not just prompts — are the new attack surface. Check Point and BeyondTrust both demonstrated that privileged container access can be weaponized to exfiltrate tokens and data without triggering user warnings, forcing organizations to add layered, independent oversight on top of vendor defaults.




