Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theft

Check Point Research disclosed that ChatGPT's internal JFrog Artifactory instance exposed a hidden channel letting one account plant instructions that a victim's ChatGPT session would silently execute, reading data from the victim's connected Gmail account and returning it to the attacker's account. The proof-of-concept was disclosed to OpenAI in late June 2026, by which time the Artifactory instance had already been decommissioned, closing the channel.

Disclosed 8 September 2026 · Record updated 13 September 2026

Impact

Proof-of-concept showed an attacker could silently exfiltrate a victim's Gmail data - and potentially data from other connected apps such as Google Drive, Microsoft Teams and GitHub - with no visible sign to the victim beyond a small 'Talked to Gmail' label. No real-world victims were reported.

Our coverage

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
  2. theregister.comhttps://theregister.com/security/2026/09/08/openais-artifactory-opened-covert-data-stealing-channel-alongside-hugging-face-attack/5295124
  3. simonwillison.nethttps://simonwillison.net/2026/Sep/12/openai-agents-rubygems