ChatGPT Flaw Lets Attackers Pull Gmail Data Across Accounts via a Hidden Channel
17 Articles
17 Articles
ChatGPT Flaw Let Attackers Hijack a Victim’s Session
The more access you give ChatGPT, the more an attacker can work with if they trick the AI into following the wrong instructions. A new Check Point finding illustrated that risk by examining ChatGPT’s code-execution environment and connected apps. Researchers showed that a planted instruction could make a victim’s session perform a hidden task using its existing permissions and relay it to another ChatGPT account. The attack did not require a sto…
Check Point Research has uncovered a serious vulnerability in ChatGPT. While the chatbot was conducting a normal conversation with the user, it was also able to secretly act on behalf of... after entering a single instruction. Full version of the page: https://ithardware.pl/aktualnosci/chatgpt_luka_gmail_openai-53895.html
ChatGPT incorrectly allows some Gmail users to read other people's mail
ChatGPT’s AI agents are able to extract sensitive material from one account and transfer it to another because they are both operating partially within the same environment. Discovered by Check Point Research (CPR) experts vulnerability Known as “coerced insiders” – its operation requires manipulating the behavior of agents rather than directly resorting to software bugs. […]
An investigation by Check Point revealed that an internal instance of Artifactory could serve as a hidden channel for a ChatGPT session to send instructions and extract data from someone else’s connected accounts. The infrastructure was removed, but the case exposes the risks of entrusting AI agents with simultaneous access to private code, services and files.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











