Deep Research agent leaked Gmail data from inside OpenAI's cloud
Because the agent made the outbound request itself, nothing crossed the victim's network for a security tool to catch.
19 Sept 2025
Radware found that an email with hidden instructions could make OpenAI's Deep Research agent read a user's Gmail and send personal data to an attacker's server, entirely from OpenAI's cloud so no traffic left the user's network.
Occurred 18 June 2025 · Disclosed 18 September 2025 · Record updated 13 September 2026
Any Deep Research user with a Gmail connector was exposed. OpenAI fixed the issue in early August 2025 before public disclosure.
Because the agent made the outbound request itself, nothing crossed the victim's network for a security tool to catch.
19 Sept 2025