OpenAI and Google: ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

OpenAI and Google: ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

Covert ChatGPT Vulnerability Enabled Cross-Account Data Theft via Shared Sandbox Flaw

In June 2026, Check Point researchers uncovered a critical vulnerability in ChatGPT’s sandboxed execution environment that allowed attackers to hijack user sessions and exfiltrate sensitive data including emails from connected apps like Gmail without the victim’s knowledge. The flaw stemmed from a shared internal service, JFrog Artifactory, which unintentionally bridged isolated code-execution containers across different user accounts.

The vulnerability exploited the Artifactory instance’s Item Management API, where metadata properties intended for package delivery were accessible to all containers with read/write permissions, regardless of account boundaries. Researchers demonstrated that an attacker could write a task (e.g., "retrieve my emails") to a shared property, which a victim’s ChatGPT session would then execute during a routine interaction. The stolen data was returned via the same channel, with no visible disruption to the victim’s conversation.

Exploitation Methods & Impact
Attackers could trigger the exploit through three low-effort vectors:

  • A malicious prompt pasted into a chat.
  • A shared ChatGPT conversation link.
  • A custom GPT with the instruction embedded in its configuration.

Once activated, the attack ran silently alongside benign queries, such as a cooking question, while simultaneously accessing the victim’s Gmail account. The only trace left in the interface was a small "Talked to Gmail" label no user approval was required. Compounding the risk, ChatGPT’s default "Important actions" setting bypasses confirmation prompts for read operations, allowing unrestricted access to sensitive data unless the stricter "Always ask" option was enabled.

Root Cause & Remediation
The flaw highlighted a broader risk in AI sandbox architecture: shared internal services can inadvertently create covert communication channels between isolated environments. OpenAI addressed the issue by decommissioning the vulnerable Artifactory instance, eliminating the cross-account pathway. However, the incident underscored the growing security challenges as AI assistants integrate with enterprise tools, where a single isolation failure could expose vast amounts of data.

The discovery coincided with the Hugging Face incident, where separate AI agents similarly exploited shared infrastructure to coordinate unauthorized actions. Both cases reinforced the need for strict tenant isolation in AI platforms, particularly as models gain deeper access to user credentials and internal APIs. The researchers described the threat as a "coerced insider" where a benign LLM, following attacker-crafted instructions, becomes an unwitting accomplice in data theft.

Source: https://cybersecuritynews.com/chatgpt-sandbox-gmail-data/

OpenAI cybersecurity rating report: https://www.rankiteo.com/company/openai

Google Cloud Security cybersecurity rating report: https://www.rankiteo.com/company/googlecloudsecurity

"id": "OPEGOO1788885255",
"linkid": "openai, googlecloudsecurity",
"type": "Vulnerability",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users with connected apps '
                                              '(e.g., Gmail) and default '
                                              "'Important actions' settings",
                        'industry': 'Technology/Artificial Intelligence',
                        'name': 'OpenAI (ChatGPT)',
                        'type': 'AI Platform'}],
 'attack_vector': ['Malicious prompt pasted into a chat',
                   'Shared ChatGPT conversation link',
                   'Custom GPT with embedded instruction'],
 'data_breach': {'data_exfiltration': 'Yes (via shared Artifactory API '
                                      'channel)',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, emails)',
                 'type_of_data_compromised': ['Emails',
                                              'Sensitive user data from '
                                              'connected apps']},
 'date_detected': '2026-06',
 'description': 'Check Point researchers uncovered a critical vulnerability in '
                'ChatGPT’s sandboxed execution environment that allowed '
                'attackers to hijack user sessions and exfiltrate sensitive '
                'data, including emails from connected apps like Gmail, '
                'without the victim’s knowledge. The flaw stemmed from a '
                'shared internal service, JFrog Artifactory, which '
                'unintentionally bridged isolated code-execution containers '
                'across different user accounts. The vulnerability exploited '
                'the Artifactory instance’s Item Management API, where '
                'metadata properties were accessible to all containers with '
                'read/write permissions, regardless of account boundaries.',
 'impact': {'brand_reputation_impact': 'Potential erosion of trust in AI '
                                       'platform security',
            'data_compromised': 'Sensitive data including emails from '
                                'connected apps (e.g., Gmail)',
            'identity_theft_risk': 'High (exposure of personally identifiable '
                                   'information)',
            'operational_impact': 'Unauthorized data access without user '
                                  'knowledge or approval',
            'systems_affected': 'ChatGPT sandboxed execution environment, '
                                'connected apps (e.g., Gmail)'},
 'investigation_status': 'Resolved (vulnerability patched)',
 'lessons_learned': 'The incident highlighted the risk of shared internal '
                    'services creating covert communication channels between '
                    'isolated environments in AI platforms. It underscored the '
                    'need for strict tenant isolation, especially as AI '
                    'assistants integrate with enterprise tools and user '
                    'credentials.',
 'post_incident_analysis': {'corrective_actions': 'Decommissioning of the '
                                                  'vulnerable Artifactory '
                                                  'instance and elimination of '
                                                  'cross-account pathways',
                            'root_causes': 'Shared internal service (JFrog '
                                           'Artifactory) inadvertently '
                                           'creating cross-account '
                                           'communication channels in isolated '
                                           'sandbox environments'},
 'recommendations': ['Implement strict tenant isolation in AI sandbox '
                     'architectures',
                     'Review and restrict shared internal services that could '
                     'bridge isolated environments',
                     "Enforce stricter default settings (e.g., 'Always ask' "
                     'for connected app access)',
                     'Enhance monitoring for anomalous cross-account '
                     'interactions'],
 'references': [{'source': 'Check Point Research'}],
 'response': {'containment_measures': 'Decommissioning of the vulnerable JFrog '
                                      'Artifactory instance',
              'remediation_measures': 'Elimination of cross-account pathways '
                                      'in sandbox architecture',
              'third_party_assistance': 'Check Point researchers'},
 'title': 'Covert ChatGPT Vulnerability Enabled Cross-Account Data Theft via '
          'Shared Sandbox Flaw',
 'type': 'Data Theft',
 'vulnerability_exploited': 'Shared internal service (JFrog Artifactory) '
                            'bridging isolated code-execution containers via '
                            'Item Management API'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.