CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6650

As cited

Copy frozen at (site build).

ai security

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research discovered a cross-account covert channel in ChatGPT that allowed attackers to execute hidden tasks within a victim's session by exploiting shared access to an internal package service. An attacker could embed instructions in a shared conversation or custom GPT, causing ChatGPT to process both the victim's visible request and the attacker's hidden task simultaneously, with results returned through a metadata-based communication path. The proof of concept demonstrated retrieval of email data from a victim's connected Gmail account and transmission to an attacker without visible indication in the user's conversation.

Why it matters: Organizations using ChatGPT with connected apps and code-execution capabilities face data exfiltration risk if sessions are shared or if malicious custom GPTs are installed; security teams should review ChatGPT app permissions (especially connected integrations like Gmail) and monitor for suspicious activity in shared conversations.

VendorsMicrosoftGoogleGitHubCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research discovered a cross-account covert channel in ChatGPT that allowed attackers to execute hidden tasks within a victim's session by exploiting shared access to an internal package service. An attacker could embed instructions in a shared conversation or custom GPT, causing ChatGPT to process both the victim's visible request and the attacker's hidden task simultaneously, with results returned through a metadata-based communication path. The proof of concept demonstrated retrieval of email data from a victim's connected Gmail account and transmission to an attacker without visible indication in the user's conversation.

Why it matters: Organizations using ChatGPT with connected apps and code-execution capabilities face data exfiltration risk if sessions are shared or if malicious custom GPTs are installed; security teams should review ChatGPT app permissions (especially connected integrations like Gmail) and monitor for suspicious activity in shared conversations.

VendorsCheck PointGitHubGoogleMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary