{"data":{"id":"472b2930-963e-4e3b-bdfe-16ba85f1e211","title":"ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel","summary":"A flaw in ChatGPT allowed attackers to extract data from victims' connected Gmail accounts by using a shared metadata storage system (a space where information is temporarily stored and accessed) to pass hidden instructions between different user sessions. The vulnerability existed in ChatGPT's code execution environment, where user containers (isolated computational spaces assigned to individual accounts) were supposed to be separated but could actually read and write to shared package delivery metadata, creating a covert communication channel. OpenAI has since fixed the issue by decommissioning the affected internal service.","solution":"OpenAI has fixed the issue. According to the report, \"the internal service involved has been decommissioned.\"","labels":["security","privacy"],"sourceUrl":"https://www.csoonline.com/article/4220203/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html","publishedAt":"2026-09-09T11:48:19.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["data_extraction","prompt_injection"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","ChatGPT","Gmail","Google Drive","Microsoft Teams","GitHub","HuggingFace","JFrog Artifactory"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-09T11:48:19.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}