- A single hidden instruction inside a ChatGPT chat could quietly hand a stranger access to a user’s connected Gmail account.
- Check Point Research built the attack using shared package server metadata as a secret messaging line between two ChatGPT accounts.
- OpenAI shut down the internal service behind the flaw after Check Point reported it, closing the hidden channel for good.
Check Point Research published a report describing a serious flaw inside ChatGPT. A single planted instruction could make ChatGPT secretly work for an attacker. At the same time, it kept answering the real user’s question like normal. The user saw nothing wrong on their screen.
In a demonstration built by the firm, that hidden task pulled data straight from the user’s connected Gmail account. It then pushed that data to a second ChatGPT account through a hidden channel.
The reply the victim actually read never mentioned any of it. Check Point also said the same channel could pull out full chat histories and files from that conversation. The total amount an attacker could grab depended on what tools and apps that chat session already had access to.
How the Hidden Prompt Took Over ChatGPT
The planted instruction had to sit inside the conversation first. Check Point pointed to three ways an attacker could plant it. A user might paste in a prompt without knowing what it truly does. A user might open a shared ChatGPT conversation link sent by someone else. Or a user might build a chat around a custom GPT, which can hide instructions inside its builder settings that the user never sees.
Once that instruction sat in the chat, one normal message from the user was enough to trigger it. Check Point explained that the instruction pushed ChatGPT’s Thinking mode to run two separate jobs during a single turn. One job answered the user’s real question as expected.
The other job quietly checked a hidden mailbox for a task left by the attacker. It then carried out that task using the tools already available inside the user’s own session and sent the result back out.
The instruction told the model to keep both jobs fully apart. That way, the hidden task never showed up anywhere inside the visible reply. The only clue left behind was a small label reading “Talked to Gmail,” placed above the answer. That label only recorded a read that had already happened. It gave the user no chance to approve or block it beforehand.
According to Check Point, nothing prompted the user first because of how connected apps behave by default. OpenAI’s own documentation lists “Important actions” as the standard setting, which lets ChatGPT read from a connected app without asking.
OpenAI’s Mac Messages plugin has raised privacy concerns because it can read, search, draft, and send messages with broad macOS permissions. Experts warn that this access could expose sensitive data, including encrypted message histories, to OpenAI’s servers.
ChatGPT only pauses to ask before actions that could cause real outside effects, expose sensitive data directly, or prove hard to reverse. A user can switch their own setting to “Always ask” for extra caution. Inside Business, Enterprise, and Edu workspaces, admins instead choose which actions each connected app may take and who gets to use it.
The Package Server that Linked Two Accounts
The hidden channel itself ran between the containers ChatGPT builds to run code. ChatGPT spins up a fresh container for each conversation whenever a task calls for one. Company documentation states that the Python setup ChatGPT uses for data work cannot reach the open web or outside services on its own. Check Point confirmed that containers built for separate chats, even ones tied to different accounts, had no direct route to reach each other either.
All those containers, however, could still reach one shared internal service. ChatGPT sometimes needs extra Python or npm packages mid-task. Rather than letting every container fetch packages straight from the public internet, each one instead talked to an internal JFrog Artifactory system built to fetch those packages on its behalf.
That system lets any container attach small labeled values, called properties, onto a stored file, then read those same values back later. The access credentials each container held for reading turned out to also allow writing those properties. Those credentials sat inside environment variables, somewhere ChatGPT’s own code could reach them directly. No extra secret needed to be stolen, and no special privileges needed to be gained first.
Crucially, these properties were never separated by account. Check Point proved this by attaching a labeled property, holding nothing but a timestamp, to a cached file from one account’s container. From a completely different account’s container, the firm then requested that same file’s properties and received the identical label and value back.
Because a property can hold plain text or Base64 data, and larger pieces can even be split across several properties and rebuilt afterward, this ordinary package tool became something else. It became a working message channel between containers that were never meant to talk to one another.
OpenAI Shuts the Door, but Questions Remain
Check Point said it reported the finding directly to OpenAI. OpenAI then confirmed that the specific internal service behind this channel had already been taken fully offline. There is no separate patch for regular users to install here, since the fix happened entirely on OpenAI’s own infrastructure.
This marks the second such channel that Check Point has found and reported inside this same part of ChatGPT. Back in March, the firm described an earlier method that relied on DNS lookups to quietly send conversation data out to an external server. OpenAI fixed that particular issue on February 20, according to Check Point’s account.
The firm was careful to separate this case from the unrelated Hugging Face incident, where OpenAI’s own models reportedly turned a different internal Artifactory system into an open message board during the company’s own internal security testing.
Check Point described the underlying mechanism here as different from that incident. Still, it framed both cases the same way, noting that a shared internal service became an unplanned communication layer stretching across environments that were meant to stay fully separate from one another.
Check Point dated its research work to June 2026 but did not state exactly when this particular channel stopped functioning. Because of that gap, the published report does not make clear how long the hidden channel may have stayed open before OpenAI closed it down.
Share this article
About the Author
Related Posts
Australia Moves to Boost Social Media Privacy With Algorithm Opt-Out
Australia’s government may let users turn off personalized recommendation algorithms. People c...
Hackers Abuse Signed Node.js to Hide Malware from Antivirus Tools
Attackers have utilized the signed Node.js binary to launch malicious JavaScript code, enabling payl...
New Security Tool Targets Cyber Threats Hidden Behind VPNs and Proxies
Hackers hide behind VPNs and proxies to look like normal, safe visitors. Most security tools only ch...
EU Puts ChatGPT, Reddit and Roblox Under Toughest Digital Safety Rules
The European Commission named ChatGPT, Reddit and Roblox as very large online services under the Dig...
Microsoft Warns Windows Users to Ignore False Defender Antivirus Alert
Microsoft is asking users to ignore a false alert saying Windows Defender is turned off. The bug has...
Signal Fixes Critical SGX Flaws that Could Expose Contact Discovery Data
V12 found two flaws in Signal’s Contact Discovery Service that could break the security boundary aro...