A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel
Date:
Wed, 09 Sep 2026 13:05:00 +0000
Description:
OpenAI has shut down this particular path, but general risk remains.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Check Point Research exposed coerced insider flaw in ChatGPTs agent architecture Containers shared
metadata via internal service, enabling crossaccount prompt injection and
data theft OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms ChatGPTs AI agents were allowed to pull sensitive data
from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways,
experts have warned.
A new report from security experts Check Point Research (CPR) dubbed the flaw coerced insider, since it revolves around persuading the agent instead of abusing a vulnerability. Coerced insider When an AI agent is given a task
that needs code execution, it handles that task in an isolated container
which also sometimes needs to install software. To enable that, without
giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves. Latest Videos From TechRadar Watch full video here:
However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can
read back the properties written by any other container.
Check Point Research confirmed the isolation gap directly: a property written from one accounts container was fully readable from a different accounts container moments later, with data too large for one property simply split into chunks and reassembled on the other end, the researchers explained. You may like Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff AI agents organized into a swarm, considered the risks of attack, and did whatever it took to achieve its goal ChatGPT might soon let you lock away your most sensitive chats
The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.
From there, the exploit turns into your usual, off-the-shelf prompt
injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features
and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while
replying to the victims question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background. What kind of information can be stolen? But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent.
The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, Google Drive , Microsoft Teams, GitHub, and similar. In Check Point Researchs demonstration, ChatGPT
retrieved the victims email data through their connected Gmail account and delivered it to the attackers session, all within a single ordinary turn, CPR stressed. What to read next Phishing the agent: Why AI guardrails arent
enough Experts manage to hack Microsoft Copilot by continually asking it questions about itself Experts say they were able to create a rogue agent in Googles AI platform with just a single edit permission
The good news is that youll likely never be exposed this way, at least not
via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research
has been commissioned. In other words, the hallways attack path has been closed.
The bad news is that this doesnt automatically mean everyones safe. This particular path might be closed, but the architectural pattern behind the
flaw could be present in other platforms, CPR warns.
Any AI assistant that operates inside an organizations trust boundary,
holding credentials, running code, and reaching connected services, can
become what Check Point Research calls a coerced insider, the report states. The model itself does not need to be malicious. It only needs to be
persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.
Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions
(not just output) as something that needs to be monitored. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/a-worrying-chatgpt-bug-let-strangers-re ad-gmail-messages-via-a-hidden-cross-account-channel
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)