ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
Summary
Researchers at Check Point discovered a security flaw in ChatGPT that allowed attackers to create a hidden communication channel between two separate user accounts, potentially letting one user access another user's data like Gmail without detection. The vulnerability exploited an internal service that wasn't designed to carry user data, breaking the isolation that is supposed to keep different accounts separated from each other. This is concerning because many organizations are connecting ChatGPT to sensitive systems like email and file storage, trusting that account boundaries will protect their data.
Classification
Affected Vendors
Related Issues
Original source: https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/
First tracked: September 8, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%