
ChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim’s Gmail Data to Another Account
Check Point Research disclosed Tuesday that a weakness in ChatGPT's code-execution sandbox let data from one user's connected Gmail account be moved into a separate, attacker-controlled ChatGPT account, with no confirmation prompt shown to the victim.
The flaw sat not in the model but in the infrastructure beneath it. Containers running individual conversations cannot address one another directly, Check Point found, but every container could reach the same internal JFrog Artifactory instance OpenAI used for package management. An item-management feature there let any container attach text metadata properties to cached items and read properties written by others, turning a package cache into ...