CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6613

As cited

Copy frozen at (site build).

ai security

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

Check Point Research disclosed a flaw in ChatGPT where a hidden instruction planted in a conversation could cause the application to exfiltrate a user's Gmail data to an attacker's account while continuing to respond normally. The vulnerability exploited ChatGPT's ability to access connected email accounts through a covert communication channel.

Why it matters: Organizations and individuals using ChatGPT with Gmail integration face data theft risk if they unknowingly process malicious prompts; practitioners should review how generative artificial intelligence (AI) tools handle connected accounts and consider restricting third-party integrations.

VendorsGoogleCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary