ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Summary
Check Point Research discovered a vulnerability in ChatGPT where a hidden instruction planted in a conversation could cause ChatGPT to secretly perform tasks (like reading Gmail data and sending it to an attacker's account) while still answering the user's question normally. The attack exploited the internal JFrog Artifactory service that manages Python packages for ChatGPT's code execution containers, which allowed different user sessions to share data through file properties that weren't kept separate by account.
Solution / Mitigation
OpenAI confirmed that the internal service behind the attack channel had been taken offline. There is no update for users to install.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
First tracked: September 8, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%