ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel
Summary
A flaw in ChatGPT allowed attackers to extract data from victims' connected Gmail accounts by using a shared metadata storage system (a space where information is temporarily stored and accessed) to pass hidden instructions between different user sessions. The vulnerability existed in ChatGPT's code execution environment, where user containers (isolated computational spaces assigned to individual accounts) were supposed to be separated but could actually read and write to shared package delivery metadata, creating a covert communication channel. OpenAI has since fixed the issue by decommissioning the affected internal service.
Solution / Mitigation
OpenAI has fixed the issue. According to the report, "the internal service involved has been decommissioned."
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4220203/chatgpt-flaw-lets-attackers-pull-gmail-data-across-accounts-via-a-hidden-channel.html
First tracked: September 9, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 95%