VulnerabilitiesHidden channel in ChatGPT's package server leaked Gmail data
Check Point Research says one ChatGPT account could plant instructions that another user's session silently carried out, using the victim's connected apps.
13 Sept 2026
Check Point Research disclosed that ChatGPT's internal JFrog Artifactory instance exposed a hidden channel letting one account plant instructions that a victim's ChatGPT session would silently execute, reading data from the victim's connected Gmail account and returning it to the attacker's account. The proof-of-concept was disclosed to OpenAI in late June 2026, by which time the Artifactory instance had already been decommissioned, closing the channel.
Disclosed 8 September 2026 · Record updated 13 September 2026
Proof-of-concept showed an attacker could silently exfiltrate a victim's Gmail data - and potentially data from other connected apps such as Google Drive, Microsoft Teams and GitHub - with no visible sign to the victim beyond a small 'Talked to Gmail' label. No real-world victims were reported.
VulnerabilitiesCheck Point Research says one ChatGPT account could plant instructions that another user's session silently carried out, using the victim's connected apps.
13 Sept 2026