Key takeaways:
- Check Point found a ChatGPT flaw that let separate user sessions communicate through an internal service.
- Attackers could send hidden instructions that made a victim’s ChatGPT session access Gmail, files, or chat history.
- The victim could receive a normal answer while ChatGPT quietly handled the attacker’s request in the background.
- OpenAI decommissioned the internal service involved, closing this specific attack path.
Researchers have found a way to get ChatGPT to access a victim’s Gmail, chat history, and files by exploiting a hidden communication channel that connects separate user accounts.
Check Point Research discovered that ChatGPT sessions belonging to different users could secretly communicate with each other through an internal service. An attacker could use that channel to send a hidden instruction to a victim’s ChatGPT session, which would then carry out the task using the access already available to the victim.
The attack could reach data from connected services such as Gmail, Google Drive, Microsoft Teams, and GitHub, depending on what the victim had connected to ChatGPT. It could also access files and conversation history available to the affected session.
The researchers demonstrated the attack by making a victim’s ChatGPT session retrieve email data from Gmail and send it back to an attacker. The worrying part was that the victim did not see the attacker’s request.